What is passive scan in ZAP?
Can you please clarify what exactly is meant by "passive scan" in the context of ZAP, the Open Source Security Testing tool? I understand it's a feature that's used for vulnerability scanning, but I'm interested in knowing the specifics. Does it involve actively sending requests to the target application, or does it operate in a more subtle manner, monitoring traffic without initiating any interactions? Also, what types of vulnerabilities does a passive scan typically uncover, and how does it compare to an active scan in terms of effectiveness and efficiency?