mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is reviewing a Python script…
A penetration tester is reviewing a Python script that uses the 'mitmproxy' library. The script sets up a proxy and captures HTTP traffic, then modifies certain requests in real time. Which of the following is the most likely purpose of this script?
⚠ Common exam trap
Watch out — candidates often confuse mitmproxy with passive sniffing tools like Wireshark, failing to recognize that mitmproxy's core feature is active interception and modification of application-layer traffic, not just passive observation or raw packet capture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To intercept and manipulate API requests for security testing
The mitmproxy library is specifically designed for man-in-the-middle interception and modification of HTTP/HTTPS traffic. By setting up a proxy and modifying requests in real time, the script's most likely purpose is to intercept and manipulate API requests for security testing, such as fuzzing parameters, injecting payloads, or bypassing client-side controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To perform passive network mapping and port scanning
Why it's wrong here
Mitmproxy is not a network mapping or port scanning utility. It functions strictly as an application-layer HTTP/HTTPS proxy, only seeing traffic that clients explicitly route through it. Passive network mapping typically involves observing broadcast traffic or ARP/spoofing taps, while port scanning actively probes endpoints with packets — both are outside mitmproxy's design scope. Tools like Nmap or p0f serve these purposes.
- ✓
To intercept and manipulate API requests for security testing
Why this is correct
Mitmproxy is purpose-built to intercept HTTP/HTTPS traffic, decrypt it, and present it for inspection and live modification. For API security testing, this lets testers alter JSON bodies, headers, query strings, and authentication tokens mid-session to test input validation, authorization bypasses, business logic flaws, and replay attacks. Its Python scripting API enables automated, conditional tampering that directly supports API fuzzing and negative test scenarios, making it a standard tool for dynamic API assessment.
- ✗
To capture raw network packets for offline analysis
Why it's wrong here
Raw packet capture is accomplished by libpcap-based tools like tcpdump or Wireshark, which intercept frames at the network interface layer, including IP, TCP, and UDP headers. Mitmproxy, in contrast, operates at the OSI application layer; it receives decrypted HTTP content after TLS termination and re-encrypts it for forwarding. It never sees low-level frame details or non-HTTP protocols such as DNS, ARP, or SSH, so it cannot provide raw captures for offline analysis. Attempting packet capture with mitmproxy would miss critical metadata and non-HTTP traffic.
- ✗
To automatically detect SQL injection vulnerabilities
Why it's wrong here
Automated SQL injection detection requires a dedicated vulnerability scanner such as sqlmap, which performs payload generation, response analysis, and database fingerprinting based on differential responses. Mitmproxy has no built-in SQLi detection logic; it is a generic HTTP intercepting proxy. While a tester could use mitmproxy to route sqlmap's traffic or manually inject payloads to observe behavior, the proxy itself does not analyze responses or decide if an injection point is exploitable. Therefore, relying on mitmproxy for automated SQLi detection conflates interception with active vulnerability scanning.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.