Whenever a penetration tester is assigned to simulate real-world attacks against a target organization, there are usually one of three types of penetration tests conducted: white box, grey box, and black box. Each type will determine what assets are exposed to both an insider threat and an external party, such as a black hat hacker.
A white box test is an easy type of penetration test as a complete knowledge of the target’s systems and network is known prior to the simulated attack. This can be beneficial to the penetration tester as they would have ample information about the target network and can better utilize tools and resources in creating, delivering, and executing payloads that would most likely be successful on the first attempt. However, there is a disadvantage to this type of penetration test. The ethical hacker or penetration tester...