PT0-002 Vulnerability Discovery and Analysis Practice Question
During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?
⚠ Common exam trap
Candidates often confuse Repeater (which is for manual, single-request testing) with Intruder (which is for automated, multi-request attacks), leading them to choose Repeater because they think it can be used for brute-forcing by manually sending requests one by one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intruder
Intruder is the correct tool because it is specifically designed for automated customized attacks, including brute-force attacks, against web application parameters. It allows the tester to define a payload position (e.g., the password field in a login request) and iterate through a list of candidate passwords, automatically resending the request with each payload value and analyzing the responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intruder
Why this is correct
Intruder is Burp Suite's dedicated automated fuzzing and brute-force engine. It enables you to define a request template, mark payload positions, and cycle through large wordlists using attack types like Sniper, Pitchfork, and Cluster Bomb. With features like payload processing, request throttling, and session handling macros, Intruder is purpose-built for credential guessing and dictionary attacks against authentication endpoints. That is why it is the correct tool for this task.
- ✗
Scanner
Why it's wrong here
Burp Scanner is designed for both passive and active vulnerability detection, such as SQL injection, XSS, and misconfigurations. It does not provide the ability to configure custom payload positions or cycle through a list of credentials, as it focuses on discovering weaknesses rather than exploiting them through repeated login attempts. Its scanning engine is not suited for brute-force authentication testing, making it the wrong choice here.
- ✗
Sequencer
Why it's wrong here
Sequencer is a statistical analysis tool that collects a sample of tokens (e.g., CSRF tokens, session IDs) and evaluates their randomness and entropy. It is used to assess whether a token generation algorithm is predictable, not to send multiple login requests with different passwords. Sequencer lacks the ability to define payload positions or run iterative attacks, so it cannot perform brute-force operations.
- ✗
Repeater
Why it's wrong here
Repeater is intended for manual request manipulation and resending a single HTTP request one at a time. While you can manually alter credentials and resend, it requires laborious human intervention for each attempt and has no built-in automation to loop through a credential list. It is ideal for subtle manual testing of one request but completely impractical for brute-force, which demands automated, high-volume request generation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.