mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Python script…
A penetration tester is analyzing a Python script used during a test. The script contains the following code: 'import requests; r = requests.get('http://target', headers={'User-Agent': 'Mozilla/5.0'}); print(r.text)'. What is the primary purpose of setting the User-Agent header in this script?
⚠ Common exam trap
Many candidates confuse the User-Agent header with mechanisms that affect rate limiting or authentication, when in fact it is purely a client identification field used for evasion and content negotiation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To mimic a legitimate browser to evade detection by web application firewalls.
Setting the User-Agent header to 'Mozilla/5.0' makes the HTTP request appear to originate from a standard web browser rather than a Python script. This helps evade detection by web application firewalls (WAFs) and other security controls that may block or flag requests with non-browser User-Agent strings, which are common indicators of automated or malicious traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To bypass IP-based rate limiting.
Why it's wrong here
Rate limiting keyed on source IP is unaffected by a User-Agent string, which the server reads only after accepting the connection from that address. The header is used to impersonate a browser so the server returns normal content rather than blocking a scripted client, which is the actual purpose in this scenario.
- ✓
To mimic a legitimate browser to evade detection by web application firewalls.
Why this is correct
The User-Agent header sets the client string sent with the HTTP request; using a Mozilla/5.0 value makes requests appear to originate from a standard browser rather than the requests library. This satisfies the stem's purpose of evading web application firewall detection.
- ✗
To authenticate to the web server.
Why it's wrong here
Authentication to a web server relies on credentials such as cookies, Basic auth headers or client certificates; a User-Agent value carries no identity proof. It is tempting because headers do participate in sessions, but here the string merely mimics a browser to avoid client-fingerprint blocking, not to prove who the requester is.
- ✗
To enable SSL/TLS encryption.
Why it's wrong here
The User-Agent header identifies the client software in the HTTP request; it has no bearing on transport encryption, which is negotiated by TLS before any header is sent. It is tempting because headers can carry security-relevant metadata, but SSL/TLS is enabled by requesting an https:// URL, not by setting a request header.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.