Courseiva
Engagement Management →easyMultiple Select

PT0-002 Engagement Management Practice Question

Which TWO of the following are types of penetration testing based on the level of knowledge provided to the tester? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Black box

Black box and white box are two common types based on knowledge level; grey box is the third.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Social engineering

    Why it's wrong here

    Social engineering is an attack vector or engagement technique, not a knowledge-based testing classification. While it can be incorporated into a penetration test engagement, it does not define the amount of prior information provided to the tester. In PenTest+ terminology, types such as black, white, and gray box refer to the tester's knowledge level, not the attack methods used.

  • ✗

    Network penetration test

    Why it's wrong here

    A network penetration test is an engagement type that focuses specifically on network infrastructure, servers, and endpoints. It describes the scope of the assessment, not the information asymmetry between the tester and the target. The knowledge-based categories (black/white/gray box) classify how much reconnaissance and internal detail the tester receives before the test, making this option incorrect.

  • ✗

    Red team

    Why it's wrong here

    Red team is an engagement type that simulates a full-scale adversarial attack, often combining technical exploits, social engineering, and physical intrusion. It is not a classification based on the level of knowledge given to the tester; rather, it defines the objective and breadth of the operation. PenTest+ distinguishes red teaming from the knowledge-based 'box' types used to categorize testing approaches.

  • ✓

    Black box

    Why this is correct

    Black box is a type of penetration testing where the tester has no prior knowledge of the target's internal structure, architecture, or credentials. This approach simulates an external, unprivileged attacker and forces testers to rely entirely on reconnaissance and vulnerability discovery from the outside. It is one of the three knowledge-based categories, alongside white box and gray box.

  • ✓

    White box

    Why this is correct

    White box is a type of penetration testing in which the tester is given full knowledge of the target environment, including source code, network diagrams, system credentials, and internal documentation. This allows for a comprehensive assessment of both internal and code-level vulnerabilities that might be missed in black box testing. It represents the opposite end of the knowledge spectrum and is also known as a 'clear box' test.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.