PT0-002 Engagement Management Practice Question
A penetration tester is hired to perform an assessment where the tester is provided with network diagrams, source code, and administrative credentials. Which type of penetration test is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
White box
In a white box test, the tester has full knowledge of the environment, including credentials and documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grey box
Why it's wrong here
Grey box testing is incorrect here because it involves only partial knowledge of the system, such as a set of low-privileged credentials or a subset of network diagrams. In a grey box engagement, the tester must still perform enumeration and privilege escalation to uncover vulnerabilities, whereas the prompt explicitly states that full knowledge and credentials are provided. This level is typically used to simulate an authenticated insider or a user with specific, limited access, not the complete access described in the assessment.
- ✗
Black box
Why it's wrong here
Black box testing is incorrect because it simulates an external attacker with zero prior knowledge of the target environment. The tester must rely solely on OSINT, port scanning, service enumeration, and manual exploitation to discover entry points, which is the opposite of being provided full knowledge and credentials. Since the prompt specifies that the assessor receives complete architectural information and valid credentials, the scenario cannot be classified as black box, as that would obscure the very information that has been explicitly granted.
- ✓
White box
Why this is correct
White box testing is the correct classification because the scenario describes a penetration tester who is given full knowledge of the system, including source code, network architecture, and authorized credentials. This testing level, also known as crystal box or clear box, allows comprehensive vulnerability identification, including deep logic flaws and configuration issues, and is often used for compliance-driven reviews or post-breach security assessments. The provision of full knowledge enables the tester to focus on exploitation and reporting without spending time on reconnaissance, directly matching the prompt's conditions.
- ✗
Red team
Why it's wrong here
Red team is incorrect because it refers to an engagement type that simulates real-world adversarial attacks to test detection and response capabilities, not a classification of the tester's knowledge level. A red team operation can be performed as black, grey, or white box depending on the client's objectives, such as testing how well the blue team detects an attack. The prompt asks for a testing knowledge level, and while a red team may be given full knowledge, the term itself does not inherently define the level of access or information provided, making it an unsuitable answer.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.