PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is analyzing a web application and wants to discover hidden API endpoints by brute-forcing common paths. Which tool is best suited for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Feroxbuster
Feroxbuster is a fast, recursive content discovery tool that supports wordlist-based brute-forcing of directories, files, and API endpoints, with automatic recursion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPScan
Why it's wrong here
WPScan is a vulnerability scanner built exclusively for WordPress installations. It enumerates WordPress core, plugins, themes, and users, and checks for known CVEs, but it cannot brute-force or discover hidden API endpoints or arbitrary web paths. Unless the target is a WordPress site and the goal is WordPress-specific vulnerability identification, WPScan is not a suitable choice for generic web content discovery.
- ✓
Feroxbuster
Why this is correct
Feroxbuster is a Rust-based recursive content discovery tool designed specifically for brute-forcing web directories and files, including API endpoints. It uses dictionary-based wordlists, supports status-code and size filtering, and can recurse into discovered directories, making it effective for mapping undocumented API routes. Its speed and flexibility with custom headers, request methods, and extension fuzzing make it the correct tool for this task.
- ✗
theHarvester
Why it's wrong here
theHarvester is an open-source intelligence (OSINT) tool that passively gathers email addresses, subdomains, and hostnames from public sources such as search engines, PGP key servers, and Shodan. It does not send HTTP requests to the target application to discover paths or endpoints; instead, it collects publicly indexed data. For active web content discovery or API endpoint brute-forcing, theHarvester is entirely inappropriate.
- ✗
Nikto
Why it's wrong here
Nikto is a web server vulnerability scanner that checks for known dangerous files, outdated server software, and misconfigurations by matching responses against a large database of vulnerability signatures. It does not perform wordlist-based brute-forcing to reveal hidden API endpoints or undocumented directories; its focus is identifying known weaknesses rather than exploratory content discovery. Because the goal is finding endpoints rather than vulnerabilities, Nikto is not applicable here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.