1. What OWASP ZAP Solves for Defenders
OWASP ZAP is a widely used web application security testing proxy and scanner that defenders and appsec teams use in authorized workflows to inspect traffic, validate vulnerabilities, and verify remediations.
OWASP ZAP fits the "Web application testing proxy / scanner (dual-use)" role in this course. Treat it as one tool in a workflow, not as a complete answer by itself. The key question is what decision quality it improves for a defender.
Before using OWASP ZAP, define the operational question first (triage, validation, exposure review, monitoring, forensics, or documentation). Tool selection should follow the question, not the other way around.