CISSP Security Assessment and Testing Practice Question
An organization wants to test its security controls by simulating an attack where the tester has no prior knowledge of the internal network. This is known as a:
⚠ Common exam trap
Test-takers frequently confuse the testing methodology (black/grey/white box) with the team structure (red team exercise), leading candidates to select 'Red team exercise' because it sounds like an attack simulation, but the question explicitly defines the knowledge level, not the team composition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Black box test
A black box test (D) is correct because the tester has no prior knowledge of the internal network, simulating an external attacker with zero inside information. This approach evaluates the security controls from an unprivileged, external perspective, relying solely on publicly available information and active reconnaissance. It is the purest form of adversarial simulation for testing perimeter defenses and detection capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grey box test
Why it's wrong here
A grey box test involves the security testers having some limited, internal knowledge of the target system, such as network diagrams, architecture documentation, or user-level credentials. This partial insight allows them to simulate an attacker who has gained an initial foothold or an insider threat, focusing on vulnerabilities accessible with that specific level of access. It does not, however, represent a completely external attacker with no prior information.
- ✗
White box test
Why it's wrong here
A white box test grants the security testers full and complete knowledge of the target system's internal workings, including access to source code, system documentation, and network configurations. This comprehensive insight enables a thorough analysis of internal vulnerabilities, code flaws, and design weaknesses, often performed by internal security teams or developers. It is fundamentally different from simulating an external attacker who possesses no prior information about the environment.
- ✗
Red team exercise
Why it's wrong here
A red team exercise is a comprehensive, goal-oriented simulation designed to test an organization's overall security posture, including its detection and response capabilities, against a sophisticated, real-world adversary. While often initiated with limited or no prior knowledge (black box), the term 'red team' primarily describes the adversarial role and the broad scope of tactics, techniques, and procedures (TTPs) employed, rather than solely defining the initial information access level of the testers.
- ✓
Black box test
Why this is correct
A black box test simulates an external attacker with absolutely no prior knowledge of the target system's internal architecture, network topology, or source code. Testers approach the system purely from an outsider's perspective, relying on public information, reconnaissance, and common attack methodologies to discover vulnerabilities. This method directly assesses how well an organization's external defenses would withstand an attack from an unknown, unprivileged adversary.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.