Burp Suite Web Security Testing
Questions about Burp Suite penetration testing tool including its components (proxy, scanner, intruder, repeater, sequencer) and related web security protocols and concepts
Questions
Which of the following tools is designed to be used by penetration testers and to fit in closely with your existing techniques?
- BIO
- Burp intruder target tab port field
- Burp scanner
- Burp spider
- Burp position tab
Which of the following will capture and replay any and all web requests?
- Proxy object
- Burp proxy
- OWASP token
- Burp position tab
- Proxy instance
By using which of the following tools will you understand how the target application functions and will have some knowledge of the HTTP protocol?
- Burp intruder
- Burp position tab
- Burp intruder port field
- Burp spider
- Proxy class
Which of the following protocols is used, if you want to terminate SSL at httpd and you need the SSL information?
- NNTP
- NIO
- SMTP
- FTP
- AJP
Which of the following is not supported by http when it is acting as a reverse proxy?
- OWASP token
- BIO
- NIO
- Web socket
- Comet
Which of the following tools is used for manually modifying and reissuing individual hyper text transfer protocol requests and analysing their responses?
- Burp repeater
- Burp position tab
- Burp intruder port field
- Burp spider
- Proxy instance
Which of the following protocols can be processed by tomcat using SSL valve?
- TCP
- HTTP
- FTP
- NNTP
- SMTP
In which of the following scanning does the burp scanner not send any new request of its own?
- Proxy instance
- OWASP token
- Burp spider
- Burp scanner passive scanning
- Burp scanner live scanning
Which of the following tabs is used to configure the details of the target server?
- Proxy interface
- Burp scanner live scanning
- Burp intruder target tab
- Burp position tab
- Burp intruder target tab port field
Which of the following includes one click transfer of interesting requests between tools?
- Burp scanner
- Burp position tab
- Burp spider
- OWASP token
- Burp suit
Which of the following conditions provides request body read and response body write?
- Function proxy
- BIO
- Simulate blocking
- NIO
- Thread exhaustion
Which of the following burp intruder target tab's fields is used to specify the IP address of the target server?
- Proxy class
- Burp intruder target tab host field
- Burp intruder target tab port field
- Burp position tab
- Burp spider
Which of the following determines the confidentiality, integrity and availability of the applications?
- Web application security testing
- OWASP token
- Burp spider
- Transport level encryption
- Output reconciliation control
Which of the following tools is used to test the quality of an application's session tokens?
- Burp spider
- Burp sequencer
- Burp position tab
- Burp intruder target tab port field
- BIO
In which of the following scanning does the scanner send various crafted requests to the application derived from a base request?
- Burp scanner active scanning
- Burp scanner passive scanning
- Burp spider
- Burp position tab
- NIO