ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is finalizing a security test plan for a multitenant SaaS portal. Leadership wants an assessment that mirrors an external attacker's perspective, uses no source code or design knowledge, and identifies exploitable weaknesses in the running application. Which testing technique best meets this need?
Gray-box security review combining code walkthroughs with credentialed scanning
White-box static code analysis performed by internal developers
Black-box penetration testing that performs dynamic analysis of the live application
Threat-modeling sessions using data-flow diagrams to map trust boundaries
Black-box penetration testing treats the application as an opaque target, giving testers no internal design or source-code information. Assessors interact with the running system exactly as an outsider would, relying on dynamic probing, input manipulation, and observation of outputs to uncover vulnerabilities. This aligns with the requirement to evaluate the application from an external attacker's viewpoint. White-box static analysis, gray-box reviews, and threat-modeling workshops all require at least some internal knowledge or focus on design rather than empirical discovery of runtime flaws, so they do not satisfy the stated constraint.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is black-box penetration testing?
Open an interactive chat with Bash
Why is dynamic analysis important in black-box penetration testing?
Open an interactive chat with Bash
How does black-box testing compare to white-box testing?
Open an interactive chat with Bash
What is black-box penetration testing?
Open an interactive chat with Bash
How is black-box testing different from white-box and gray-box testing?
Open an interactive chat with Bash
Why is black-box penetration testing preferred for SaaS environments?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .