Specialist-tool bridges
A broad QA engineer should recognize specialist tools and know the evidence needed for a handoff. This chapter intentionally stops at the boundary where another GimmeJob learning path owns the depth.
General investigation → performance? k6/JMeter → security? ZAP/Burp → accessibility? axe/Lighthouse/tree → automation/integration? Appium Inspector/grpcurl/WebSocket/Kafka → specialist pathk6 and JMeter: when to hand off to Performance
k6 and Apache JMeter can generate scripted load and collect request-level performance results. They belong to a performance-testing workflow when the question involves concurrency, sustained load, capacity or latency distributions under controlled demand.
Practical use: Before load generation, define workload model, environment, success criteria and monitoring. Use a simple single-user API check first to prove functional correctness.
Caveat: Running a load tool against an unapproved environment can be operationally disruptive. Authorization and capacity boundaries are part of the test design.
ZAP and Burp Suite: when to hand off to Security
OWASP ZAP and Burp Suite combine interception with security-oriented scanning and testing workflows. They become specialist tools when the objective is vulnerability discovery or adversarial validation rather than ordinary request diagnosis.
Practical use: Use explicit scope and authorization, start with passive/observational features where appropriate, and follow the Security curriculum for threat modeling and safe active testing.
Caveat: A scanner finding is not automatically a confirmed vulnerability; reproduce and assess context/impact.
Lighthouse, axe and the accessibility tree: when to hand off to Accessibility
Automated accessibility tools such as axe-core and Lighthouse can detect rule-based issues and browser accessibility-tree problems. They do not cover all WCAG requirements or human assistive-technology interaction.
Practical use: Use automated findings as fast feedback, inspect semantic roles/names/states, then hand off to keyboard, screen-reader and standards-based testing for complete coverage.
Caveat: A zero-violation automated scan is not proof of accessibility.
Appium Inspector, grpcurl, WebSocket and Kafka tooling
Appium Inspector helps inspect mobile automation element trees; grpcurl exercises gRPC services; browser/CLI tools can inspect WebSocket messaging; Kafka command-line tooling can produce/consume records for event-pipeline investigation.
Practical use: Use these tools to establish the failing boundary and a reproducible artifact, then move to Automation or API & Integration learning for framework design, contracts, event semantics and deeper test strategy.
Caveat: Protocol-specific tooling can mutate real systems by creating records, sessions or messages. Use test identities, isolated topics/queues and clear cleanup rules.
Summary
- This chapter covers 4 required concepts while keeping tool/formula details tied to a practical decision.
- Definitions, scope, assumptions and caveats matter more than a number or a tool name by itself.
- Claims that depend on a standard or product are grounded in the source registry below.