Courseiva
Security Assessment and TestingeasyMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:

⚠ Common exam trap

Many candidates confuse the test's knowledge level (black, white, grey) with the test's origin (internal vs. external), leading candidates to incorrectly select 'Internal test' because they associate 'no prior knowledge' with an external perspective, but the question explicitly asks for the type based on knowledge, not location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Black box

A black box penetration test simulates an external attacker with no prior knowledge of the target environment. The testers are given no credentials, network diagrams, or internal details, forcing them to perform reconnaissance and exploitation from an outsider's perspective. This aligns directly with the scenario where the third party has 'no prior knowledge of the internal network.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Black box

    Why this is correct

    Black box testing simulates an external attacker with no prior knowledge of the target system's internal structure, network architecture, or source code. The assessor approaches the system as an unprivileged outsider, attempting to discover vulnerabilities through publicly available information and external reconnaissance. This method effectively evaluates an organization's perimeter defenses and its ability to withstand real-world, unknown threats, making it ideal for a third-party assessment where initial knowledge is withheld.

  • White box

    Why it's wrong here

    White box testing provides the assessor with complete and comprehensive knowledge of the target environment, including full access to system architecture diagrams, network configurations, and often source code. This deep insight allows for thorough analysis of internal logic, security controls, and potential vulnerabilities that might be missed by external testing. While highly effective for detailed code review and internal security audits, it does not simulate an external attacker's perspective, which is often the primary objective for a general third-party assessment.

  • Grey box

    Why it's wrong here

    Grey box testing involves the assessor having partial or limited knowledge of the target system, such as user-level credentials, network diagrams for specific segments, or access to internal documentation. This approach aims to simulate an attacker who has gained some initial foothold or an insider threat with restricted access. While it offers a balance between efficiency and realism by focusing on specific areas, it is not the most appropriate choice when the goal is to assess an organization's defenses from a completely unknown, external perspective, as implied by a general third-party assessment without specified knowledge.

  • Internal test

    Why it's wrong here

    An internal test refers to an assessment conducted from within the organization's network perimeter, simulating an insider threat or an attacker who has successfully breached the external defenses. While the knowledge level for an internal test can vary (black, grey, or white box), the term primarily defines the *location* of the assessment, not the *information* provided to the tester. The question describes a third party performing an assessment without specifying location or initial knowledge, making 'black box' a more direct and common fit for evaluating external defenses from an unknown perspective.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.