A penetration tester is testing an internet web application and notices a WAF is present. The penetration tester is confident that the wordlist will allow brute forcing into the system but trigger the WAF. Which of the following would best allow the tester access to the application discreetly if there is ample time?
A. Perform a Slowloris attack on the web application.
B. Attack, intrude the network, and disable the WAF.
C. Fingerprint the WAF and create custom exploits.
D. Bypass the WAF using MITM.