skip to content

OWASP ZAP

The open-source DAST proxy: crawl an application, replay traffic through active scan rules, and drive a baseline scan from CI. Interviewers ask what a scanner cannot reach.

on this pageshow

explore

questions

121 · 8 sections

In OWASP ZAP, which capabilities live in the core program and which arrive as add-ons?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Core is one versioned program: the command line, the control API, the active-scan engine, and the alert and context models. Almost everything else — the local proxy, the passive-scan engine, the crawlers, automation, reports — ships as separately versioned add-ons.

open as a page

How is the set of add-ons in a ZAP distribution or container image actually decided?

level: middleimportance: must knowfreq 55%
basics
~20 s

A list in ZAP's core repository names every add-on folded into a main release, pinning each by download URL and SHA-256 hash; entries flagged core are the smaller core distribution. Container images then freeze that set at image-build time.

open as a page

In ZAP, what is the real difference between starting the program with `-cmd` and with `-daemon`?

level: middleimportance: must knowfreq 62%
basics
~20 s

Lifetime, not the interface. Both switches turn the window off and both bring up the local listener. -cmd runs the registered work inline and then shuts down; -daemon runs it on a background thread and loops.

open as a page

In OWASP ZAP, what does an `httpsender` script implement, and which traffic does it see?

level: middleimportance: must knowfreq 45%
basics
~20 s

An httpsender script implements two entry points, sendingRequest and responseReceived, each handed the message, an initiator naming which part of ZAP caused it, and a send helper. It sits on the sending path every component uses.

open as a page

Which ZAP container image tag should a CI job pull, and what does the `bare` tag leave out?

level: juniorimportance: should knowfreq 55%
basics
~20 s

Pull the default tag unless you know you do not need what it carries. The bare tag is a JRE-on-Alpine image with bash and curl added: no browser, no X server, no Python, and one architecture.

open as a page

What is the difference between ZAP's -certpubdump and -certfulldump, and which one does a browser need?

level: juniorimportance: must knowfreq 52%
basics
~20 s

-certpubdump writes ZAP's root CA certificate; -certfulldump writes that same certificate and then appends its private key. A browser needs the first. The second contains a secret, because the appended key is what signs certificates.

open as a page

In an OWASP ZAP context, what is an include or exclude regex actually matched against?

level: middleimportance: must knowfreq 62%
basics
~20 s

A full, case-insensitive match against the URL with everything from the first question mark onward removed. A prefix will not match because the pattern must describe the whole string, and a rule written against a query parameter can never fire.

open as a page

In an OWASP ZAP automation plan, what do a context's urls and includePaths entries become?

level: middleimportance: should knowfreq 46%
basics
~20 s

Both become include regexes on the context, but by different routes. Each urls entry is checked as a URI and then gets a wildcard appended; each includePaths entry is added exactly as written, so a bare URL there matches only itself.

open as a page

In OWASP ZAP, what decides whether a URL is in scope, and what has no say in it?

level: middleimportance: should knowfreq 54%
basics
~20 s

Contexts decide it, and nothing else does. A URL is in scope when some context with its in-scope flag set includes it and no in-scope context excludes it. Exclusion crosses context boundaries, and scope has no storage of its own.

open as a page

In OWASP ZAP, which component provides the local proxy listener a browser points at, and what stays in core?

level: middleimportance: should knowfreq 42%
basics
~20 s

The network add-on provides it. Its LocalServer class binds the configured address and port, and ExtensionNetwork registers the -host and -port arguments. Core keeps deprecated proxy classes plus four live listener interfaces so older add-ons still compile.

open as a page

Which ZAP login methods ship in core, which come from the authhelper add-on, and why does the difference matter?

level: middleimportance: must knowfreq 70%
basics
~20 s

Core registers five authentication method types: manual, http, form, json and script. The authhelper add-on adds browser-based, client-script-based and auto-detect logins. A plan may name all eight, but the last three fail unless that add-on is installed.

open as a page

How does ZAP decide, part-way through a scan, that an authenticated user is still logged in?

level: middleimportance: must knowfreq 52%
basics
~20 s

A context's verification method matches a logged-in or logged-out regex against traffic. Its strategy decides which traffic: the request, the response, both, or — the default — a separate poll request sent to a URL you nominate on a cadence you set.

open as a page

A ZAP scan finished clean but every page reached was the login page. How do you diagnose the form login?

level: seniorimportance: must knowfreq 65%
basics
~20 s

Read the two recorded authentication messages and compare the login request that was actually sent against a real browser login. The login step reports only preparation and send failures, so a rejected login leaves no error behind.

open as a page

An authenticated ZAP scan finishes anonymous with no error reported — how do you diagnose it?

level: seniorimportance: must knowfreq 55%
basics
~20 s

Re-login is triggered only when the verification method returns a negative verdict, so a silent drop means verification kept saying yes. Read the five stats.auth.state. counters: four of them return authenticated and only one of those rests on a real match.

open as a page

In a ZAP automation plan, what does a context's authentication block hold and what do its users entries hold?

level: juniorimportance: should knowfreq 55%
basics
~20 s

A context's authentication block says how to log in: the method plus its parameters, such as the login request URL and body. The users list says who logs in, each entry carrying a name and a username and password.

open as a page

Why does ZAP's `openapi` import reach endpoints that its `spider` add-on never finds?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A definition lists every operation whether or not anything links to it, and the openapi add-on sends a real request for each one. A link-following crawl can only enqueue what a response already points at.

open as a page

Why does ZAP ship two browser-driven crawlers, and what can spiderClient see that spiderAjax cannot?

level: middleimportance: must knowfreq 62%
basics
~20 s

ZAP's spiderAjax add-on drives a browser with a bundled Crawljax but only watches HTTP traffic on a proxy it starts itself. The client add-on's spiderClient adds a ZAP browser extension that reads the DOM, so it finds content spiderAjax cannot.

open as a page

In ZAP's traditional `spider` add-on, what does `parseRobotsTxt: true` do with a `Disallow` line?

level: middleimportance: must knowfreq 68%
basics
~20 s

It mines it. With parseRobotsTxt on, the spider seeds /robots.txt at the host root, then reads Disallow and Allow lines through the same code path and queues each path as a new target. It never obeys them.

open as a page

Which host does a ZAP `openapi` import contact, and what overrides that choice?

level: seniorimportance: must knowfreq 55%
basics
~20 s

The document decides: every server entry it declares becomes a base URL, falling back to the authority the definition came from. The job's targetUrl parameter overrides that; without it, a multi-server document is contacted at every server.

open as a page

In ZAP's zap-baseline.py wrapper, what does -j add, and which browser crawler does it now run?

level: juniorimportance: should knowfreq 50%
basics
~20 s

The -j flag adds a browser-driven crawl on top of the traditional spider. It now runs the client spider by default, and --ajax-spider switches back to the AJAX spider. The wrappers' own usage text still claims the opposite default.

open as a page

In OWASP ZAP, where does the active-scan engine live, and where do its attack rules come from?

level: juniorimportance: must knowfreq 58%
basics
~20 s

ZAP's active-scan engine ships in core, in org.parosproxy.paros.core.scanner. The rules that craft the payloads ship separately, as scan-rule add-ons. A build with no rule add-ons still has a working scheduler with almost nothing to run.

open as a page

In ZAP, what is a passive scan rule handed to work with, and what stops it sending a request?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A ZAP passive scan rule implements the core PassiveScanner interface, which hands it a recorded HTTP message and that message's history id. The interface declares no send method, so a rule can only read traffic already captured.

open as a page

In ZAP, how does the pscan add-on's passive engine get the messages that its rules scan?

level: middleimportance: must knowfreq 60%
basics
~20 s

ZAP's pscan add-on runs a PassiveScanController that walks the History table by record id rather than the live wire. For each record it queues a PassiveScanTask, which re-reads the message and runs every enabled passive rule.

open as a page

In OWASP ZAP, what do a scan rule's `Plugin.AttackStrength` and `Plugin.AlertThreshold` each control?

level: middleimportance: must knowfreq 70%
basics
~20 s

AttackStrength sets how hard a rule tries: how many payloads and requests it spends per parameter. AlertThreshold sets how much evidence it demands before raising anything. They are separate dials, and only the threshold has an OFF value.

open as a page

In a ZAP active scan, which parts of a request may rules change by default, and which are left alone?

level: middleimportance: must knowfreq 62%
basics
~20 s

By default a ZAP active scan may change query-string parameters, post-data parameters and a plain request body. Cookies, HTTP headers and URL path segments are left alone: TARGET_INJECTABLE_DEFAULT omits them, and no scan policy can add them.

open as a page

On an OWASP ZAP alert, what do the risk value and the confidence value each tell you?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Risk is how damaging the finding would be if it is real. Confidence is how sure the scan rule is that it is real. They are two separate fields on the alert, set independently.

open as a page

Which fields does a ZAP alertFilter job match an alert on, and how is each compared?

level: middleimportance: must knowfreq 55%
basics
~20 s

The ruleId is compared for equality against the alert's scan-rule id and against its alertRef. The url, parameter, attack and evidence clauses are exact strings unless their own regex flag is set, and methods is a set. Any clause you omit matches everything.

open as a page

In a ZAP report job, where do the risks, confidences and sections lists sit, and what do they default to?

level: middleimportance: must knowfreq 55%
basics
~10 s

They are job-level keys, siblings of parameters rather than entries inside it. Omit any one and the report includes everything that key could filter: every risk, every confidence band, every section the template declares.

open as a page

In ZAP's alertFilters add-on, how does a global alert filter differ from a context one?

level: juniorimportance: should knowfreq 45%
basics
~20 s

A global alert filter is tested against every alert and is stored in the add-on's own options, so it survives the next session. A context filter applies only inside its named context and is saved with that context.

open as a page

In ZAP's automation report job, what does the template parameter actually refer to?

level: juniorimportance: should knowfreq 50%
basics
~10 s

The template's own directory name under ZAP's reports folder - its id, not the display title written inside template.yaml and not the output file name. Leave it empty and the job uses risk-confidence-html.

open as a page

What do the exit codes of ZAP's packaged baseline scan script mean, and what does its -I flag change?

level: juniorimportance: must knowfreq 55%
basics
~20 s

zap-baseline.py exits 1 if a rule marked FAIL alerted, 2 if only WARN-bucket rules did, 0 if at least one rule ran and raised nothing, and 3 for everything else. -I removes only the exit-2 branch.

open as a page

In ZAP's control API, what do the segments of `/JSON/core/view/version/` mean, and which request types exist?

level: middleimportance: must knowfreq 58%
basics
~10 s

Format first, then component, request type and name. JSON is the response format, core the component, view the request type, version the call. The request types are view, action, other and pconn.

open as a page

In ZAP's packaged scans, what is the tab-separated file passed with -c, and what is on each line?

level: middleimportance: must knowfreq 50%
basics
~10 s

It is a per-rule verdict file: each tab-separated line pins one numeric scan-rule id to IGNORE, INFO, WARN or FAIL, with an optional note. Any rule the file omits defaults to WARN.

open as a page

In ZAP's automation framework, what does a plan file contain and what decides the order the work runs in?

level: middleimportance: must knowfreq 60%
basics
~20 s

A ZAP automation plan is a YAML file with two parts: env, which names the environment the run acts on, and jobs, an ordered list of units of work. Jobs run top to bottom, in the order written.

open as a page

What does each of ZAP's three packaged scan scripts run against a target, and how do they differ?

level: middleimportance: must knowfreq 62%
basics
~20 s

zap-baseline.py crawls the target and passively inspects the traffic, never attacking. zap-full-scan.py adds an active scan with all rules enabled. zap-api-scan.py never crawls: it imports an API definition and attacks only what the import reached.

open as a page

Does ZAP check that you are allowed to scan a target, and what does it ship instead?

level: juniorimportance: must knowfreq 68%
basics
~20 s

ZAP performs no ownership or authorisation check on a target — nothing in it resolves who owns a host. It ships only a permission warning on rendered screens such as its welcome text and Quick Start panel.

open as a page

What makes OWASP ZAP a natural fit for an unattended pipeline rather than a desk tool?

level: middleimportance: must knowfreq 58%
basics
~20 s

The automatable surface is where the project invests: a core -daemon option that runs it headless, one control API, and client libraries generated from that API — so an add-on's own API reaches the clients without anyone hand-writing a binding.

open as a page

What does ZAP's Control.Mode setting restrict, and which value does a headless run start in?

level: middleimportance: must knowfreq 60%
basics
~20 s

Control.Mode takes safe, protect, standard or attack, and is persisted under the key view.mode with standard as its default. A headless run gets standard — unrestricted — because nothing ZAP ships for automation ever sets it.

open as a page

In ZAP, what does protect mode check against scope, and at what point in a scan?

level: seniorimportance: must knowfreq 50%
basics
~20 s

Protect mode checks only the start nodes of a scan, once, when the scan is asked to start. Over the API the refusal is MODE_VIOLATION. Nothing re-checks the mode afterwards, so it bounds admission rather than traffic.

open as a page

OWASP ZAP is Apache-2.0 with no paid tier — what does that settle in a tool choice, and what does it not?

level: middleimportance: should knowfreq 50%
basics
~20 s

Apache-2.0 with no paid tier settles price and access: nothing to buy, no seat to provision per CI runner, the same build everywhere. It does not settle legal review, because the shipped package bundles code under several other licences.

open as a page