exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 352 discussion

Actual exam question from CompTIA's SY0-601
Question #: 352
Topic #: 1
[All SY0-601 Questions]

An enterprise has hired an outside security firm to conduct penetration testing on its network and applications. The firm has been given the documentation only available to the customers of the applications. Which of the following BEST represents the type of testing that will occur?

  • A. Bug bounty
  • B. Black-box
  • C. Gray-box
  • D. White-box
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NunoF4
Highly Voted 2 years, 4 months ago
C Black=unknown info white=full info grey=partial info
upvoted 23 times
...
[Removed]
Highly Voted 2 years, 4 months ago
Selected Answer: C
Because the company only has SOME information about the environment, this is a gray box.
upvoted 6 times
...
HCM1985
Most Recent 1 year, 2 months ago
Selected Answer: B
Imo this is a black box, since we have no idea about the software workings besides from a user perspective. A gray box usually provides some minor/basic info on how the software works.
upvoted 1 times
...
Gabuu
1 year, 3 months ago
Answer is C
upvoted 1 times
...
Teleco0997
1 year, 7 months ago
Selected Answer: C
partial information has been shared = gray box
upvoted 1 times
...
Selected Answer: C
The BEST representation of the type of testing that will occur in this scenario is Gray-box testing. Gray-box testing is a testing approach that combines elements of both black-box and white-box testing. In gray-box testing, the tester has partial knowledge or limited access to the internal workings and details of the system being tested. In this case, the outside security firm has been given documentation that is only available to customers of the applications, indicating that they have some level of insight into the system.
upvoted 2 times
...
milktea810182
2 years, 2 months ago
Selected Answer: A
documentation , so the answer is A.
upvoted 1 times
...
SophyQueenCR82
2 years, 3 months ago
The type of testing that will occur in this scenario is black-box testing. Black-box testing is a type of penetration testing where the tester has no prior knowledge of the system being tested and is given minimal information, such as an application's user documentation or a URL for a web application. The objective is to simulate an external attacker and test the system's ability to resist attacks from an unknown threat. The other options, bug bounty, gray-box, and white-box testing, involve different levels of access to the system being tested and different objectives.
upvoted 2 times
SophyQueenCR82
2 years, 3 months ago
In gray-box testing, the tester has some limited knowledge or access to the network or applications, such as having access to a user account or partial access to the source code.
upvoted 1 times
...
...
sdc939
2 years, 4 months ago
Selected Answer: C
C. Gray-box
upvoted 2 times
...
pmmg
2 years, 4 months ago
Selected Answer: C
To be White Box, they would also have to have knowledge of all of the infrastructure.
upvoted 4 times
Shermszn
2 years, 4 months ago
I agree
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...