Penetration Test Types: Unknown vs Known Environment
Which of the following best describes a penetration test that resembles an actual external attack?
Community Votes
82% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to map real-world attacker behavior to specific testing methodologies, with the common trap being confusion between white-box (known) and black-box (unknown) approaches.
This page clarifies the distinction between penetration test scopes, specifically identifying that an unknown environment best simulates a real-world external attack. It establishes why black-box testing is the correct choice for this scenario.
Candidates often select 'Partially known environment' or 'Bug bounty', failing to recognize that these do not fully replicate the total lack of prior intelligence an external attacker possesses.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An unknown environment, also known as black-box testing, provides the tester with no prior information about the target system. This mirrors the reality of an external attack where a malicious actor has no insider knowledge and must discover vulnerabilities through reconnaissance and exploitation, making it the best description for resembling an actual external attack.Why the Other Options Are Wrong
A known environment (white-box) provides full access and documentation, which is too easy compared to a real attack. A partially known environment (gray-box) offers some credentials or info, which doesn't match the zero-knowledge state of an external threat. A bug bounty is a program model, not a technical test scope definition, and often involves public disclosure rules that differ from a direct penetration test simulation.Community Comment Notes
Community members consistently highlight that 'black box' or 'unknown environment' are synonymous in this context. As one commenter noted, "Blackbox (or unknown environment)- the consultant is given no privileged information... useful for simulating the behavior of an external threat." Another user reinforced this by stating, "Unknown environment is when the pen tester is given no information... in efforts to simulate a real external attack."Exam Strategy
When analyzing security assessment questions, focus on the level of information provided to the tester. If the goal is to simulate an outsider with no inside info, always choose 'Unknown' or 'Black-box'. If the goal is thoroughness or audit compliance, look for 'Known' or 'White-box'.
Frequently Asked Questions
What is the difference between unknown and partially known environments?
An unknown environment gives the tester zero prior information (black-box), while a partially known environment provides some details like network diagrams or limited credentials (gray-box).
Why isn't a bug bounty considered a penetration test here?
A bug bounty is a crowdsourced security program model. While it may involve testing, it is not a defined technical methodology like black-box or white-box testing used in professional assessments.