A rules of engagement (ROE) document for a penetration test specifies a 'black-box' testing approach. What does this mean for the penetration tester?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because black-box penetration testing simulates an external attacker with no prior knowledge, requiring the tester to perform full reconnaissance to discover systems, services, and vulnerabilities. A is wrong because full knowledge of architecture, source code, and credentials describes white-box testing.
Full explanation below image
Full Explanation
B is correct because black-box penetration testing simulates an external attacker with no prior knowledge, requiring the tester to perform full reconnaissance to discover systems, services, and vulnerabilities. A is wrong because full knowledge of architecture, source code, and credentials describes white-box testing. C is wrong because scope is defined separately from the knowledge model; black-box applies to any scope. D is wrong because the knowledge model (black/white/grey) does not restrict the testing methods; rules of engagement define allowed techniques separately.