A blind web application test means that the tester has no prior knowledge of the application ' s internal workings. The best tool for automated scanning and vulnerability detection is a web application proxy such as OWASP ZAP.
ZAP (Option A):
OWASP Zed Attack Proxy (ZAP) is a widely used web application scanner for finding common vulnerabilities (e.g., SQL injection, XSS, authentication flaws).
It provides passive and active scanning features to test web applications for security weaknesses.
[Reference: CompTIA PenTest+ PT0-003 Official Study Guide - "Web Application Testing Tools", Incorrect options:, Option B (Nmap): Nmap is a network scanning tool, not specialized for web application testing., Option C (Wfuzz): Wfuzz is a fuzzer for brute-force attacks, but it is not a full web vulnerability scanner., Option D (Trufflehog): Trufflehog is used for secrets detection in repositories, not web testing., , , , ]
Submit