Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?

⚠ Common exam trap

Candidates often confuse Repeater (which is for manual, single-request testing) with Intruder (which is for automated, multi-request attacks), leading them to choose Repeater because they think it can be used for brute-forcing by manually sending requests one by one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intruder

Intruder is the correct tool because it is specifically designed for automated customized attacks, including brute-force attacks, against web application parameters. It allows the tester to define a payload position (e.g., the password field in a login request) and iterate through a list of candidate passwords, automatically resending the request with each payload value and analyzing the responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Intruder

    Why this is correct

    Intruder is Burp Suite's dedicated automated fuzzing and brute-force engine. It enables you to define a request template, mark payload positions, and cycle through large wordlists using attack types like Sniper, Pitchfork, and Cluster Bomb. With features like payload processing, request throttling, and session handling macros, Intruder is purpose-built for credential guessing and dictionary attacks against authentication endpoints. That is why it is the correct tool for this task.

  • ✗

    Scanner

    Why it's wrong here

    Burp Scanner is designed for both passive and active vulnerability detection, such as SQL injection, XSS, and misconfigurations. It does not provide the ability to configure custom payload positions or cycle through a list of credentials, as it focuses on discovering weaknesses rather than exploiting them through repeated login attempts. Its scanning engine is not suited for brute-force authentication testing, making it the wrong choice here.

  • ✗

    Sequencer

    Why it's wrong here

    Sequencer is a statistical analysis tool that collects a sample of tokens (e.g., CSRF tokens, session IDs) and evaluates their randomness and entropy. It is used to assess whether a token generation algorithm is predictable, not to send multiple login requests with different passwords. Sequencer lacks the ability to define payload positions or run iterative attacks, so it cannot perform brute-force operations.

  • ✗

    Repeater

    Why it's wrong here

    Repeater is intended for manual request manipulation and resending a single HTTP request one at a time. While you can manually alter credentials and resend, it requires laborious human intervention for each attempt and has no built-in automation to loop through a credential list. It is ideal for subtle manual testing of one request but completely impractical for brute-force, which demands automated, high-volume request generation.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.