OWASP ZAP
The open-source DAST proxy: crawl an application, replay traffic through active scan rules, and drive a baseline scan from CI. Interviewers ask what a scanner cannot reach.
on this pageshowhide
explore
- Program and Packaging16 questions
- Desktop, Daemon and Container5 questions
- Core and Add-Ons6 questions
- Scripting Hooks5 questions
- Traffic Capture11 questions
- Proxy in the Path5 questions
- Contexts and Scope6 questions
- Logged-In Access11 questions
- Configuring the Login5 questions
- Keeping the Session6 questions
- Building the Request List16 questions
- Traditional Spider5 questions
- Browser-Driven Crawls6 questions
- Definitions as Input5 questions
- Scan Engines21 questions
- Watching Traffic5 questions
- Sending Attacks5 questions
- Input Vectors6 questions
- Policies and Thresholds5 questions
- Findings and Output14 questions
- Risk and Confidence4 questions
- Alert Filters5 questions
- Report Templates5 questions
- Machine-Driven Runs22 questions
- Driving the Program10 questions
- Ready-Made Entry Points12 questions
- Permission and Fit10 questions
- Authorised Targets5 questions
- Comparable Tools5 questions
questions
121 · 8 sectionsIn OWASP ZAP, which capabilities live in the core program and which arrive as add-ons?
basics
~20 sCore is one versioned program: the command line, the control API, the active-scan engine, and the alert and context models. Almost everything else — the local proxy, the passive-scan engine, the crawlers, automation, reports — ships as separately versioned add-ons.
How is the set of add-ons in a ZAP distribution or container image actually decided?
basics
~20 sA list in ZAP's core repository names every add-on folded into a main release, pinning each by download URL and SHA-256 hash; entries flagged core are the smaller core distribution. Container images then freeze that set at image-build time.
In ZAP, what is the real difference between starting the program with `-cmd` and with `-daemon`?
basics
~20 sLifetime, not the interface. Both switches turn the window off and both bring up the local listener. -cmd runs the registered work inline and then shuts down; -daemon runs it on a background thread and loops.
In OWASP ZAP, what does an `httpsender` script implement, and which traffic does it see?
basics
~20 sAn httpsender script implements two entry points, sendingRequest and responseReceived, each handed the message, an initiator naming which part of ZAP caused it, and a send helper. It sits on the sending path every component uses.
Which ZAP container image tag should a CI job pull, and what does the `bare` tag leave out?
basics
~20 sPull the default tag unless you know you do not need what it carries. The bare tag is a JRE-on-Alpine image with bash and curl added: no browser, no X server, no Python, and one architecture.
What is the difference between ZAP's -certpubdump and -certfulldump, and which one does a browser need?
basics
~20 s-certpubdump writes ZAP's root CA certificate; -certfulldump writes that same certificate and then appends its private key. A browser needs the first. The second contains a secret, because the appended key is what signs certificates.
In an OWASP ZAP context, what is an include or exclude regex actually matched against?
basics
~20 sA full, case-insensitive match against the URL with everything from the first question mark onward removed. A prefix will not match because the pattern must describe the whole string, and a rule written against a query parameter can never fire.
In an OWASP ZAP automation plan, what do a context's urls and includePaths entries become?
basics
~20 sBoth become include regexes on the context, but by different routes. Each urls entry is checked as a URI and then gets a wildcard appended; each includePaths entry is added exactly as written, so a bare URL there matches only itself.
In OWASP ZAP, what decides whether a URL is in scope, and what has no say in it?
basics
~20 sContexts decide it, and nothing else does. A URL is in scope when some context with its in-scope flag set includes it and no in-scope context excludes it. Exclusion crosses context boundaries, and scope has no storage of its own.
In OWASP ZAP, which component provides the local proxy listener a browser points at, and what stays in core?
basics
~20 sThe network add-on provides it. Its LocalServer class binds the configured address and port, and ExtensionNetwork registers the -host and -port arguments. Core keeps deprecated proxy classes plus four live listener interfaces so older add-ons still compile.
Which ZAP login methods ship in core, which come from the authhelper add-on, and why does the difference matter?
basics
~20 sCore registers five authentication method types: manual, http, form, json and script. The authhelper add-on adds browser-based, client-script-based and auto-detect logins. A plan may name all eight, but the last three fail unless that add-on is installed.
How does ZAP decide, part-way through a scan, that an authenticated user is still logged in?
basics
~20 sA context's verification method matches a logged-in or logged-out regex against traffic. Its strategy decides which traffic: the request, the response, both, or — the default — a separate poll request sent to a URL you nominate on a cadence you set.
A ZAP scan finished clean but every page reached was the login page. How do you diagnose the form login?
basics
~20 sRead the two recorded authentication messages and compare the login request that was actually sent against a real browser login. The login step reports only preparation and send failures, so a rejected login leaves no error behind.
An authenticated ZAP scan finishes anonymous with no error reported — how do you diagnose it?
basics
~20 sRe-login is triggered only when the verification method returns a negative verdict, so a silent drop means verification kept saying yes. Read the five stats.auth.state. counters: four of them return authenticated and only one of those rests on a real match.
In a ZAP automation plan, what does a context's authentication block hold and what do its users entries hold?
basics
~20 sA context's authentication block says how to log in: the method plus its parameters, such as the login request URL and body. The users list says who logs in, each entry carrying a name and a username and password.
Why does ZAP's `openapi` import reach endpoints that its `spider` add-on never finds?
basics
~20 sA definition lists every operation whether or not anything links to it, and the openapi add-on sends a real request for each one. A link-following crawl can only enqueue what a response already points at.
Why does ZAP ship two browser-driven crawlers, and what can spiderClient see that spiderAjax cannot?
basics
~20 sZAP's spiderAjax add-on drives a browser with a bundled Crawljax but only watches HTTP traffic on a proxy it starts itself. The client add-on's spiderClient adds a ZAP browser extension that reads the DOM, so it finds content spiderAjax cannot.
In ZAP's traditional `spider` add-on, what does `parseRobotsTxt: true` do with a `Disallow` line?
basics
~20 sIt mines it. With parseRobotsTxt on, the spider seeds /robots.txt at the host root, then reads Disallow and Allow lines through the same code path and queues each path as a new target. It never obeys them.
Which host does a ZAP `openapi` import contact, and what overrides that choice?
basics
~20 sThe document decides: every server entry it declares becomes a base URL, falling back to the authority the definition came from. The job's targetUrl parameter overrides that; without it, a multi-server document is contacted at every server.
In ZAP's zap-baseline.py wrapper, what does -j add, and which browser crawler does it now run?
basics
~20 sThe -j flag adds a browser-driven crawl on top of the traditional spider. It now runs the client spider by default, and --ajax-spider switches back to the AJAX spider. The wrappers' own usage text still claims the opposite default.
In OWASP ZAP, where does the active-scan engine live, and where do its attack rules come from?
basics
~20 sZAP's active-scan engine ships in core, in org.parosproxy.paros.core.scanner. The rules that craft the payloads ship separately, as scan-rule add-ons. A build with no rule add-ons still has a working scheduler with almost nothing to run.
In ZAP, what is a passive scan rule handed to work with, and what stops it sending a request?
basics
~20 sA ZAP passive scan rule implements the core PassiveScanner interface, which hands it a recorded HTTP message and that message's history id. The interface declares no send method, so a rule can only read traffic already captured.
In ZAP, how does the pscan add-on's passive engine get the messages that its rules scan?
basics
~20 sZAP's pscan add-on runs a PassiveScanController that walks the History table by record id rather than the live wire. For each record it queues a PassiveScanTask, which re-reads the message and runs every enabled passive rule.
In OWASP ZAP, what do a scan rule's `Plugin.AttackStrength` and `Plugin.AlertThreshold` each control?
basics
~20 sAttackStrength sets how hard a rule tries: how many payloads and requests it spends per parameter. AlertThreshold sets how much evidence it demands before raising anything. They are separate dials, and only the threshold has an OFF value.
In a ZAP active scan, which parts of a request may rules change by default, and which are left alone?
basics
~20 sBy default a ZAP active scan may change query-string parameters, post-data parameters and a plain request body. Cookies, HTTP headers and URL path segments are left alone: TARGET_INJECTABLE_DEFAULT omits them, and no scan policy can add them.
On an OWASP ZAP alert, what do the risk value and the confidence value each tell you?
basics
~10 sRisk is how damaging the finding would be if it is real. Confidence is how sure the scan rule is that it is real. They are two separate fields on the alert, set independently.
Which fields does a ZAP alertFilter job match an alert on, and how is each compared?
basics
~20 sThe ruleId is compared for equality against the alert's scan-rule id and against its alertRef. The url, parameter, attack and evidence clauses are exact strings unless their own regex flag is set, and methods is a set. Any clause you omit matches everything.
In a ZAP report job, where do the risks, confidences and sections lists sit, and what do they default to?
basics
~10 sThey are job-level keys, siblings of parameters rather than entries inside it. Omit any one and the report includes everything that key could filter: every risk, every confidence band, every section the template declares.
In ZAP's alertFilters add-on, how does a global alert filter differ from a context one?
basics
~20 sA global alert filter is tested against every alert and is stored in the add-on's own options, so it survives the next session. A context filter applies only inside its named context and is saved with that context.
In ZAP's automation report job, what does the template parameter actually refer to?
basics
~10 sThe template's own directory name under ZAP's reports folder - its id, not the display title written inside template.yaml and not the output file name. Leave it empty and the job uses risk-confidence-html.
What do the exit codes of ZAP's packaged baseline scan script mean, and what does its -I flag change?
basics
~20 szap-baseline.py exits 1 if a rule marked FAIL alerted, 2 if only WARN-bucket rules did, 0 if at least one rule ran and raised nothing, and 3 for everything else. -I removes only the exit-2 branch.
In ZAP's control API, what do the segments of `/JSON/core/view/version/` mean, and which request types exist?
basics
~10 sFormat first, then component, request type and name. JSON is the response format, core the component, view the request type, version the call. The request types are view, action, other and pconn.
In ZAP's packaged scans, what is the tab-separated file passed with -c, and what is on each line?
basics
~10 sIt is a per-rule verdict file: each tab-separated line pins one numeric scan-rule id to IGNORE, INFO, WARN or FAIL, with an optional note. Any rule the file omits defaults to WARN.
In ZAP's automation framework, what does a plan file contain and what decides the order the work runs in?
basics
~20 sA ZAP automation plan is a YAML file with two parts: env, which names the environment the run acts on, and jobs, an ordered list of units of work. Jobs run top to bottom, in the order written.
What does each of ZAP's three packaged scan scripts run against a target, and how do they differ?
basics
~20 szap-baseline.py crawls the target and passively inspects the traffic, never attacking. zap-full-scan.py adds an active scan with all rules enabled. zap-api-scan.py never crawls: it imports an API definition and attacks only what the import reached.
Does ZAP check that you are allowed to scan a target, and what does it ship instead?
basics
~20 sZAP performs no ownership or authorisation check on a target — nothing in it resolves who owns a host. It ships only a permission warning on rendered screens such as its welcome text and Quick Start panel.
What makes OWASP ZAP a natural fit for an unattended pipeline rather than a desk tool?
basics
~20 sThe automatable surface is where the project invests: a core -daemon option that runs it headless, one control API, and client libraries generated from that API — so an add-on's own API reaches the clients without anyone hand-writing a binding.
What does ZAP's Control.Mode setting restrict, and which value does a headless run start in?
basics
~20 sControl.Mode takes safe, protect, standard or attack, and is persisted under the key view.mode with standard as its default. A headless run gets standard — unrestricted — because nothing ZAP ships for automation ever sets it.
In ZAP, what does protect mode check against scope, and at what point in a scan?
basics
~20 sProtect mode checks only the start nodes of a scan, once, when the scan is asked to start. Over the API the refusal is MODE_VIOLATION. Nothing re-checks the mode afterwards, so it bounds admission rather than traffic.
OWASP ZAP is Apache-2.0 with no paid tier — what does that settle in a tool choice, and what does it not?
basics
~20 sApache-2.0 with no paid tier settles price and access: nothing to buy, no seat to provision per CI runner, the same build everywhere. It does not settle legal review, because the shipped package bundles code under several other licences.