Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil ECSS Exam - Topic 2 Question 119 Discussion

Steve, a professional pen tester, was hired by an organization to assess its cybersecurity. The organization provided Steve with details such as network topology documents, asset inventory, and valuation information. This information helped Steve complete the penetration test successfully, and he provided a snapshot of the organization's current security posture.Identify the penetration testing strategy followed by Steve in the above scenario.
A) White-box testing
B) Goal oriented penetration testing
C) Black box testing
D) Grey box testing

Eccouncil ECSS Exam - Topic 2 Question 119 Discussion

Actual exam question for Eccouncil's ECSS exam
Question #: 119
Topic #: 2
[All ECSS Questions]

Steve, a professional pen tester, was hired by an organization to assess its cybersecurity. The organization provided Steve with details such as network topology documents, asset inventory, and valuation information. This information helped Steve complete the penetration test successfully, and he provided a snapshot of the organization's current security posture.

Identify the penetration testing strategy followed by Steve in the above scenario.

Show Suggested Answer Hide Answer
Suggested Answer: A

In the scenario described, Steve is provided with comprehensive information about the organization's network, including topology documents, asset inventory, and valuation information.This approach is indicative ofwhite-box testing, which is a penetration testing strategy where the tester has full knowledge of the system being tested12.

White-box testing allows for a thorough examination of the internal workings of the system, as the tester has access to all information, including source code, architecture diagrams, and other documentation.This level of access enables the tester to perform a more detailed and complete security assessment, as opposed to black-box testing, where the tester has no prior knowledge of the system, or grey-box testing, which is a combination of both white and black-box testing methods12.

In this case, Steve's ability to provide a snapshot of the organization's current security posture is greatly enhanced by the detailed information provided to him, which is a hallmark of the white-box testing methodology.


Contribute your Thoughts:

0/2000 characters
Janey
2 days ago
I think it's A) White-box testing. He had all the details.
upvoted 0 times
...
Isaac
7 days ago
But isn’t D) Grey box more accurate? It’s not complete transparency.
upvoted 0 times
...
Vanda
12 days ago
A) White-box makes sense. Full access to documents means full visibility.
upvoted 0 times
...
Zona
18 days ago
I lean towards D) Grey box. There’s a mix of known and unknown factors.
upvoted 0 times
...
Laine
23 days ago
Definitely A) White-box. The organization provided extensive data.
upvoted 0 times
...
Roslyn
28 days ago
Agreed, but could it be D) Grey box testing? He had some info but not everything.
upvoted 0 times
...
Aleta
1 month ago
I think it's A) White-box testing. He had all the details.
upvoted 0 times
...
Luann
1 month ago
Not sure about that, could be goal-oriented too.
upvoted 0 times
...
Aleisha
1 month ago
Agree, white-box makes sense here.
upvoted 0 times
...
Lang
2 months ago
Surprised they gave him so much info! Isn't that risky?
upvoted 0 times
...
Serita
2 months ago
I think it's more like grey box testing. He had some details but not everything.
upvoted 0 times
...
Deeanna
2 months ago
Definitely white-box testing! He had all the info.
upvoted 0 times
...
Verona
2 months ago
I feel like it could also be goal-oriented testing, but I guess that depends on whether the focus was on specific vulnerabilities or just the overall posture.
upvoted 0 times
...
Clare
4 months ago
I remember a practice question about this! If he had all that information, it leans more towards white-box testing, right?
upvoted 0 times
...
Jeanice
4 months ago
I'm not entirely sure, but it sounds like grey box testing could fit too, since he had some insider info but not complete access.
upvoted 0 times
...
Merlyn
4 months ago
I think this might be white-box testing since Steve had access to detailed documents and information about the network.
upvoted 0 times
...

Save Cancel