The focus of John’s testing is understanding the motives, methods, and identity of potential attackers. This type of approach aligns with Intelligence-Led Security Testing.
Intelligence-Led Security Testing uses real-world threat intelligence to simulate realistic cyberattack scenarios. It provides insight into adversary behavior, motivations, and techniques, helping organizations assess their resilience against targeted threats.
Such testing answers the why, how, and who questions of potential attacks and is used to validate security controls based on threat actor profiles and campaigns.
Why the Other Options Are Incorrect:
A. White box testing: The tester has full knowledge of systems and configurations; it focuses on internal vulnerabilities, not adversary motives.
C. Black box testing: The tester has no prior knowledge of the system; it focuses on external attacks, not on intelligence-driven insights about attackers.
Conclusion:
John is performing Intelligence-Led Security Testing, which combines threat intelligence with security assessment to evaluate real-world risks.
Final Answer: B. Intelligence-led security testing
Explanation Reference (Based on CTIA Study Concepts):
In CTIA, intelligence-led testing integrates threat intelligence with penetration testing to replicate realistic adversary scenarios.