CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
During a web application assessment, a tester wants Burp Suite Scanner to identify vulnerabilities by analyzing HTTP traffic that has already been captured through the proxy, without sending any additional crafted requests to the live application, to reduce the risk of account lockouts. Which scan type should the tester run?
- AActive scan
- BCrawl (spider)
- CPassive scan
- DIntruder sniper attack
Show answer & explanationAnswer & explanation
Correct answer: C. Passive scan
A passive scan reviews previously observed traffic for indicators of vulnerabilities without transmitting new payloads to the target, making it safer for sensitive or fragile applications. An active scan sends new probing requests, a crawl maps site structure, and Intruder is used for automated payload injection, not vulnerability analysis of existing traffic.
Why the other options are wrong
- A. Active scans send additional live requests, risking lockouts or disruption.
- B. Crawling discovers application structure but is not a vulnerability scan.
- D. Intruder is used for brute-force/fuzzing attacks, not passive analysis.
Burp Suite Passive Scanning
A Burp Scanner mode that inspects traffic already captured by the proxy to flag potential vulnerabilities without sending new requests to the target.
- Lower risk than active scanning
- Detects issues like missing security headers, information leakage
- Often used first before running an active scan
Memory trick: Crawl first, then Peek quietly (passive) before Poking (active)