New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 7 Question 69 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 69
Topic #: 7
[All CSSLP Questions]

In which of the following testing methods is the test engineer equipped with the knowledge of system and designs test cases or test data based on system knowledge?

Show Suggested Answer Hide Answer
Suggested Answer: D

Graybox testing is a combination of whitebox testing and blackbox testing. In graybox testing, the test engineer is equipped with the

knowledge of system and designs test cases or test data based on system knowledge. The security tester typically performs graybox testing

to find vulnerabilities in software and network system.

Answer C is incorrect. Whitebox testing is a testing technique in which an organization provides full knowledge about the infrastructure

to the testing team. The information, provided by the organization, often includes network diagrams, source codes, and IP addressing

information of the infrastructure to be tested.

Answer A is incorrect. Integration testing is a logical extension of unit testing. It is performed to identify the problems that occur when

two or more units are combined into a component. During integration testing, a developer combines two units that have already been tested

into a component, and tests the interface between the two units. Although integration testing can be performed in various ways, the

following three approaches are generally used:

The top-down approach

The bottom-up approach

The umbrella approach

Answer B is incorrect. Regression testing can be performed any time when a program needs to be modified either to add a feature or

to fix an error. It is a process of repeating Unit testing and Integration testing whenever existing tests need to be performed again along with

the new tests. Regression testing is performed to ensure that no existing errors reappear, and no new errors are introduced.


Contribute your Thoughts:

0/2000 characters
Rebbeca
3 months ago
C makes the most sense, but I can see the argument for D too.
upvoted 0 times
...
Youlanda
3 months ago
I disagree, regression testing doesn't require that level of system knowledge.
upvoted 0 times
...
Roxane
4 months ago
A little surprised that people think it's anything but C.
upvoted 0 times
...
Ellen
4 months ago
I thought it was D, graybox testing also uses some system knowledge.
upvoted 0 times
...
Bev
4 months ago
Definitely C, whitebox testing is all about knowing the internals!
upvoted 0 times
...
Tora
4 months ago
I’m a bit confused; could regression testing also involve some system knowledge? I need to think this through more.
upvoted 0 times
...
Margarett
4 months ago
I practiced a question similar to this, and I think integration testing focuses more on how components work together rather than system knowledge.
upvoted 0 times
...
Ariel
5 months ago
I'm not entirely sure, but I remember something about graybox testing combining both whitebox and blackbox techniques.
upvoted 0 times
...
Leatha
5 months ago
I think this might be related to whitebox testing since it involves knowledge of the internal workings of the system.
upvoted 0 times
...
Bette
5 months ago
Hmm, this seems like a straightforward calculation, but I want to double-check the formulas to make sure I get the right answer.
upvoted 0 times
...
Marnie
5 months ago
I'm a bit confused on this one. I know the three stakeholder categories, but I'm not sure which one is not represented. I'll have to review my notes to make sure I understand the question correctly.
upvoted 0 times
...

Save Cancel