Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Proxy

Burp Proxy intercepts and allows modification of HTTP/HTTPS requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Repeater

    Why it's wrong here

    Burp Repeater is a post-capture tool used to manually modify and resend a single HTTP request, allowing a tester to tweak headers, parameters, or body content and observe the response. It operates on a request already saved from the Proxy's HTTP history or another source; it does not sit between the browser and server as a live intermediary. Live interception, where traffic is paused and altered in transit, is exclusively the function of Burp Proxy, not Repeater.

  • ✗

    Sequencer

    Why it's wrong here

    Burp Sequencer is a statistical analysis module that evaluates the randomness and predictability of session tokens, cookies, and other security-sensitive data. It consumes a sample of captured tokens or a token file, then runs entropy and correlation tests—it does not interact with live traffic at all. Sequencer never touches the HTTP request/response stream in real time, so it cannot be used for interception during a web test.

  • ✗

    Intruder

    Why it's wrong here

    Burp Intruder is an automated attack tool that takes a captured base request, marks payload positions, and quickly fires many modified requests to fuzz parameters or brute-force values. It works offline from the live conversation, relying on a saved request template rather than monitoring or pausing actual browser-server traffic. Intruder is designed for high-volume automated testing, not for manual, real-time inspection and alteration of individual requests, which is Proxy's role.

  • ✓

    Proxy

    Why this is correct

    Burp Proxy is the component that acts as an intercepting forward proxy between the tester's browser and the target web application. With intercept mode enabled, it captures each HTTP/S request, lets the tester pause, inspect, modify, and forward it before the server sees it, and performs the same for responses. This live, bidirectional control over traffic in real time is exactly what makes Proxy the correct tool for request interception during a web application penetration test.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.