SY0-701 Question 471
Single answerPenetration testing: Physical , Offensive , Defensive , Integrated , Known environment , Partially known environment , Unknown environmentA financial services company hires a third-party firm to evaluate how well its security team can detect and respond to a realistic attack. The testers are given only the company name and a small set of public IP addresses. They are authorized to attempt social engineering, network exploitation, and badge-gated office access without notifying the internal defenders in advance. Which type of penetration test BEST matches this engagement?
- A
An integrated test in an unknown environment
- B
A defensive test in a known environment
- C
A physical test in a partially known environment
- D
An offensive test in a known environment
Show answer and explanation
Correct answer: A
Explanation
The best answer is an integrated test in an unknown environment. In Security+ terminology, an integrated test assesses multiple domains together, such as cyber, social engineering, and physical access, rather than isolating one area. The requirement that the internal defenders not be notified in advance also supports a realistic assessment of monitoring and incident response effectiveness. The limited information provided to the testers aligns with an unknown environment, commonly associated with black-box testing, where the team starts with little to no internal knowledge. By contrast, a known environment corresponds to white-box testing with extensive internal details, and a partially known environment corresponds to gray-box testing with limited but meaningful insider information. These distinctions are consistent with common penetration testing best practices and terminology used across security training and industry guidance such as NIST technical security assessment references and standard penetration testing methodologies.
- A. Correct.
Correct. This scenario combines multiple attack paths, including physical access attempts, social engineering, and technical exploitation, while specifically measuring the blue team's ability to detect and respond. That aligns with an integrated test, which evaluates coordinated offensive activity against both technical and physical controls. Because the testers receive only minimal information such as the company name and public IP space, the scope most closely matches an unknown environment, often called a black-box style engagement.
- B. Incorrect.
Incorrect. A defensive test focuses on validating protective controls and response from the defender perspective, but the scenario explicitly describes a third-party team conducting active attacks across several vectors, which is offensive activity used to test defenders. It is also not a known environment, because the testers were not given detailed internal knowledge such as network diagrams, credentials, or architecture documentation.
- C. Incorrect.
Incorrect. The presence of badge-gated office access and social engineering might tempt someone to choose physical testing, but the engagement is broader than physical security alone. It also includes network exploitation and is intended to assess detection and response across the organization. In addition, the information provided is more limited than partially known; only public-facing information was given, which better fits an unknown environment.
- D. Incorrect.
Incorrect. Offensive testing does involve active exploitation techniques, but this option is incomplete because it ignores the integrated nature of the exercise, which includes physical, social, and technical vectors together. It is also wrong on the environment classification: a known environment would provide substantial internal details, which the testers do not have here.