Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is conducting vulnerability…

A penetration tester is conducting vulnerability scanning on a web application that uses a Web Application Firewall (WAF). The scanner triggers a WAF block after several requests. Which of the following techniques would be MOST effective to continue scanning while evading the WAF?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Randomize request parameters and headers

Randomizing request parameters and headers (option B) is the most effective WAF evasion technique here because it breaks the signature and pattern-matching heuristics WAFs rely on, making each request appear unique and preventing the scanner from being fingerprinted and blocked after repeated identical payloads. Varying parameter order, casing, encoding, and header values (e.g., User-Agent, Referer) also helps slip past rate- and anomaly-based rules. Increasing scan speed (A) would generate more suspicious traffic and trigger the WAF even faster. HTTP/2 multiplexing (C) only changes transport framing and does not alter the request signatures a WAF inspects. A full TCP connect scan (D) is a port-scanning technique and is irrelevant to evading a WAF at the application layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase scan speed

    Why it's wrong here

    Raising scan speed generates more requests per second, which reinforces the rate-based signatures the WAF already triggered, deepening the block. Speed increases are tempting for finishing scans quickly, but throttling or randomising request timing is what actually avoids rate thresholds.

  • ✓

    Randomize request parameters and headers

    Why this is correct

    Varying parameters and headers per request breaks the signature patterns a WAF uses to correlate and block traffic, so the scanner's payloads no longer match known attack fingerprints. This satisfies the stem's constraint of continuing the scan after a block without altering the underlying vulnerability checks.

  • ✗

    Use HTTP/2 multiplexing

    Why it's wrong here

    HTTP/2 multiplexing sends many concurrent streams over one connection, which does not alter request payloads or timing patterns and can amplify rate-based detection. It is tempting because multiplexing improves throughput, but WAF evasion requires distributing or delaying requests, not parallelising them.

  • ✗

    Perform a full TCP connect scan

    Why it's wrong here

    A full TCP connect scan completes the three-way handshake for every port, producing more connection events and log entries that rate-based WAF rules readily flag. Connect scans are tempting for reliability, but stealthier half-open or throttled scanning is what reduces the request volume the WAF counts.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.