mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: Is planning a penetration test of its internal…
An organization is planning a penetration test of its internal network. The test team has been given network diagrams, source code access, and administrative credentials. This type of testing is known as:
⚠ Common exam trap
Watch out — candidates often confuse 'red team testing' with 'white-box testing' because both involve internal knowledge, but red team testing is defined by its adversarial objectives and operational scope, not by the level of information disclosure, whereas the question's key differentiator is the explicit provision of source code and credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
White-box testing
White-box testing (also known as clear-box or structural testing) is characterized by the test team having full knowledge of the internal system architecture, including network diagrams, source code, and administrative credentials. This level of access allows testers to perform a thorough analysis of the application logic, configuration weaknesses, and potential backdoors that would be invisible in a black-box approach. The scenario explicitly states the team was given these artifacts, making white-box testing the correct classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Black-box testing
Why it's wrong here
Black-box testing involves providing the penetration testers with no prior internal knowledge of the target system's architecture, source code, or internal configurations. Testers simulate an external attacker with zero-knowledge, focusing solely on publicly available interfaces and common vulnerabilities without any privileged information. This approach is primarily suitable for assessing external attack surfaces from an unprivileged perspective, mirroring an opportunistic outsider.
- ✗
Red team testing
Why it's wrong here
Red team testing describes an adversarial simulation where a dedicated team attempts to compromise an organization's security posture using real-world tactics, techniques, and procedures (TTPs). While a red team operation often employs black-box or gray-box *knowledge levels* regarding the target, "red team" fundamentally defines the *role* and *objective* (adversarial emulation against an organization's defenses) rather than the specific level of information provided about a single system's internals.
- ✓
White-box testing
Why this is correct
White-box testing, also known as clear-box or glass-box testing, provides the penetration testers with complete and comprehensive knowledge of the target system's internal architecture, source code, network diagrams, and configurations. This full disclosure allows for a thorough examination of internal logic, potential vulnerabilities in code implementation, and misconfigurations that might be missed by external-only approaches, leading to a very deep and detailed security assessment of the system's inner workings.
- ✗
Gray-box testing
Why it's wrong here
Gray-box testing involves providing the penetration testers with some, but not complete, knowledge of the target system's internal workings. This typically includes access to documentation like architecture diagrams, user accounts, or network maps, but not full source code or administrative credentials. It simulates an attacker with some insider knowledge or a privileged user, balancing the efficiency of a more informed test with a realistic attack scenario from a partially privileged perspective.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.