Courseiva
Web Application and Injection AttackseasyMultiple ChoiceObjective-mapped

CEH Web Application and Injection Attacks Practice Question

Which Burp Suite tool is specifically designed to automate customized attacks against web applications, such as brute-forcing login credentials or fuzzing parameters?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Intruder

Burp Intruder is used for automating customized attacks, including brute force and fuzzing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Repeater

    Why it's wrong here

    Burp Repeater is designed for manually modifying and reissuing individual HTTP requests to a target server. It allows security testers to precisely control request parameters, headers, and body content, observing the server's response in detail. This tool is ideal for step-by-step analysis of application behavior and testing specific vulnerabilities, but it lacks any automated payload generation or attack capabilities.

  • Scanner

    Why it's wrong here

    Burp Scanner is an automated web vulnerability scanner that actively probes web applications for common security flaws such as SQL injection, cross-site scripting, and path traversal. It intelligently analyzes application responses to identify potential vulnerabilities and provides detailed reports. While automated, its primary function is broad vulnerability discovery, not targeted, payload-driven automation of specific attack types like brute-forcing or fuzzing custom input fields.

  • Intruder

    Why this is correct

    Burp Intruder is specifically engineered to automate custom, payload-driven attacks against web applications. Users define "payload positions" within a base request, then configure various payload sets and attack types (e.g., Sniper, Battering Ram, Pitchfork) to systematically inject values into those positions. This powerful tool is ideal for brute-forcing, fuzzing, credential stuffing, and other repetitive tasks requiring automated request modification and response analysis.

  • Proxy

    Why it's wrong here

    Burp Proxy acts as an intercepting HTTP/S proxy, allowing security professionals to view, modify, and drop all traffic passing between their browser and the target web application. It is fundamental for capturing requests and responses, enabling manual analysis and feeding data to other Burp tools. While crucial for the overall testing process, the Proxy itself does not automate attacks or perform payload injection; it facilitates the manual manipulation of individual requests.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.