CISSP Security Assessment and Testing Practice Question
A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:
⚠ Common exam trap
Many candidates confuse the test's knowledge level (black, white, grey) with the test's origin (internal vs. external), leading candidates to incorrectly select 'Internal test' because they associate 'no prior knowledge' with an external perspective, but the question explicitly asks for the type based on knowledge, not location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Black box
A black box penetration test simulates an external attacker with no prior knowledge of the target environment. The testers are given no credentials, network diagrams, or internal details, forcing them to perform reconnaissance and exploitation from an outsider's perspective. This aligns directly with the scenario where the third party has 'no prior knowledge of the internal network.'
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Black box
Why this is correct
Black box testing simulates an external attacker with no prior knowledge of the target system's internal structure, network architecture, or source code. The assessor approaches the system as an unprivileged outsider, attempting to discover vulnerabilities through publicly available information and external reconnaissance. This method effectively evaluates an organization's perimeter defenses and its ability to withstand real-world, unknown threats, making it ideal for a third-party assessment where initial knowledge is withheld.
- ✗
White box
Why it's wrong here
White box testing provides the assessor with complete and comprehensive knowledge of the target environment, including full access to system architecture diagrams, network configurations, and often source code. This deep insight allows for thorough analysis of internal logic, security controls, and potential vulnerabilities that might be missed by external testing. While highly effective for detailed code review and internal security audits, it does not simulate an external attacker's perspective, which is often the primary objective for a general third-party assessment.
- ✗
Grey box
Why it's wrong here
Grey box testing involves the assessor having partial or limited knowledge of the target system, such as user-level credentials, network diagrams for specific segments, or access to internal documentation. This approach aims to simulate an attacker who has gained some initial foothold or an insider threat with restricted access. While it offers a balance between efficiency and realism by focusing on specific areas, it is not the most appropriate choice when the goal is to assess an organization's defenses from a completely unknown, external perspective, as implied by a general third-party assessment without specified knowledge.
- ✗
Internal test
Why it's wrong here
An internal test refers to an assessment conducted from within the organization's network perimeter, simulating an insider threat or an attacker who has successfully breached the external defenses. While the knowledge level for an internal test can vary (black, grey, or white box), the term primarily defines the *location* of the assessment, not the *information* provided to the tester. The question describes a third party performing an assessment without specifying location or initial knowledge, making 'black box' a more direct and common fit for evaluating external defenses from an unknown perspective.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.