What it is
Detects whether a web application firewall sits between the internet and the site, and which one. A WAF filters HTTP traffic to block common attacks such as SQL injection, cross-site scripting and file inclusion.
Why it matters
A WAF changes what every other test means, since the response you get may be coming from the filter rather than the application behind it. Knowing the product also tells you the rule set in play, and WAFs have bypasses and vulnerabilities of their own.