Burp Suite Web Security Testing

Questions about Burp Suite penetration testing tool including its components (proxy, scanner, intruder, repeater, sequencer) and related web security protocols and concepts

15 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following tools is designed to be used by penetration testers and to fit in closely with your existing techniques?

  1. BIO
  2. Burp intruder target tab port field
  3. Burp scanner
  4. Burp spider
  5. Burp position tab
Question 2 Multiple Choice (Single Answer)

Which of the following will capture and replay any and all web requests?

  1. Proxy object
  2. Burp proxy
  3. OWASP token
  4. Burp position tab
  5. Proxy instance
Question 3 Multiple Choice (Single Answer)

By using which of the following tools will you understand how the target application functions and will have some knowledge of the HTTP protocol?

  1. Burp intruder
  2. Burp position tab
  3. Burp intruder port field
  4. Burp spider
  5. Proxy class
Question 4 Multiple Choice (Single Answer)

Which of the following protocols is used, if you want to terminate SSL at httpd and you need the SSL information?

  1. NNTP
  2. NIO
  3. SMTP
  4. FTP
  5. AJP
Question 5 Multiple Choice (Single Answer)

Which of the following is not supported by http when it is acting as a reverse proxy?

  1. OWASP token
  2. BIO
  3. NIO
  4. Web socket
  5. Comet
Question 6 Multiple Choice (Single Answer)

Which of the following tools is used for manually modifying and reissuing individual hyper text transfer protocol requests and analysing their responses?

  1. Burp repeater
  2. Burp position tab
  3. Burp intruder port field
  4. Burp spider
  5. Proxy instance
Question 7 Multiple Choice (Single Answer)

Which of the following protocols can be processed by tomcat using SSL valve?

  1. TCP
  2. HTTP
  3. FTP
  4. NNTP
  5. SMTP
Question 8 Multiple Choice (Single Answer)

In which of the following scanning does the burp scanner not send any new request of its own?

  1. Proxy instance
  2. OWASP token
  3. Burp spider
  4. Burp scanner passive scanning
  5. Burp scanner live scanning
Question 9 Multiple Choice (Single Answer)

Which of the following tabs is used to configure the details of the target server?

  1. Proxy interface
  2. Burp scanner live scanning
  3. Burp intruder target tab
  4. Burp position tab
  5. Burp intruder target tab port field
Question 10 Multiple Choice (Single Answer)

Which of the following includes one click transfer of interesting requests between tools?

  1. Burp scanner
  2. Burp position tab
  3. Burp spider
  4. OWASP token
  5. Burp suit
Question 11 Multiple Choice (Single Answer)

Which of the following conditions provides request body read and response body write?

  1. Function proxy
  2. BIO
  3. Simulate blocking
  4. NIO
  5. Thread exhaustion
Question 12 Multiple Choice (Single Answer)

Which of the following burp intruder target tab's fields is used to specify the IP address of the target server?

  1. Proxy class
  2. Burp intruder target tab host field
  3. Burp intruder target tab port field
  4. Burp position tab
  5. Burp spider
Question 13 Multiple Choice (Single Answer)

Which of the following determines the confidentiality, integrity and availability of the applications?

  1. Web application security testing
  2. OWASP token
  3. Burp spider
  4. Transport level encryption
  5. Output reconciliation control
Question 14 Multiple Choice (Single Answer)

Which of the following tools is used to test the quality of an application's session tokens?

  1. Burp spider
  2. Burp sequencer
  3. Burp position tab
  4. Burp intruder target tab port field
  5. BIO
Question 15 Multiple Choice (Single Answer)

In which of the following scanning does the scanner send various crafted requests to the application derived from a base request?

  1. Burp scanner active scanning
  2. Burp scanner passive scanning
  3. Burp spider
  4. Burp position tab
  5. NIO