Courseiva

CEH Introduction to Ethical Hacking Practice Question

A penetration tester is reviewing the difference between a white-box, black-box, and gray-box assessment for a client's new e-commerce platform. The client wants the most realistic simulation of an external attacker with no inside knowledge, but also wants the tester to spend time efficiently rather than performing lengthy reconnaissance. Which assessment type best matches the client's stated priorities?

⚠ Common exam trap

The trap here is equating realism exclusively with black-box testing and overlooking that gray-box testing can be both realistic and time-efficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Gray-box assessment

Gray-box testing supplies the tester with partial knowledge, such as a standard user account or network diagrams, which simulates an attacker who has some insider access while cutting down on time-consuming discovery. This matches the client's dual goal: realistic external-style testing and efficient use of the testing window. Full-knowledge and no-knowledge assessments each satisfy only one of those priorities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Black-box assessment

    Why it's wrong here

    Black-box testing provides the most realistic external attacker simulation because the tester starts with no information, but it requires extensive reconnaissance that consumes time. The client wants to avoid lengthy reconnaissance, so pure black-box does not satisfy both stated priorities. Realism alone is not the only criterion here.

  • ✗

    White-box assessment

    Why it's wrong here

    A white-box assessment gives the tester full knowledge of source code, architecture, and credentials, which maximizes efficiency but does not simulate an external attacker with no inside knowledge. The client explicitly wants realism from an outsider's perspective, so full disclosure contradicts that requirement even though it saves time.

  • ✓

    Gray-box assessment

    Why this is correct

    Gray-box testing balances realism and efficiency by giving the tester partial information, such as user-level credentials or architecture diagrams, while still requiring discovery of many attack paths. This simulates an attacker with some insider knowledge and reduces wasted reconnaissance time. It matches the client's desire for realistic external simulation without the full overhead of black-box work.

  • ✗

    Double-blind assessment

    Why it's wrong here

    A double-blind assessment keeps both the tester and the target organization's defenders unaware, which tests detection and response realism but does not reduce the tester's reconnaissance burden. It is a variation of black-box testing in terms of information provided to the tester. The client's priority of efficiency is not addressed by this approach.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.