Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is analyzing a web application and wants to discover hidden API endpoints by brute-forcing common paths. Which tool is best suited for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Feroxbuster

Feroxbuster is a fast, recursive content discovery tool that supports wordlist-based brute-forcing of directories, files, and API endpoints, with automatic recursion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is a vulnerability scanner built exclusively for WordPress installations. It enumerates WordPress core, plugins, themes, and users, and checks for known CVEs, but it cannot brute-force or discover hidden API endpoints or arbitrary web paths. Unless the target is a WordPress site and the goal is WordPress-specific vulnerability identification, WPScan is not a suitable choice for generic web content discovery.

  • ✓

    Feroxbuster

    Why this is correct

    Feroxbuster is a Rust-based recursive content discovery tool designed specifically for brute-forcing web directories and files, including API endpoints. It uses dictionary-based wordlists, supports status-code and size filtering, and can recurse into discovered directories, making it effective for mapping undocumented API routes. Its speed and flexibility with custom headers, request methods, and extension fuzzing make it the correct tool for this task.

  • ✗

    theHarvester

    Why it's wrong here

    theHarvester is an open-source intelligence (OSINT) tool that passively gathers email addresses, subdomains, and hostnames from public sources such as search engines, PGP key servers, and Shodan. It does not send HTTP requests to the target application to discover paths or endpoints; instead, it collects publicly indexed data. For active web content discovery or API endpoint brute-forcing, theHarvester is entirely inappropriate.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web server vulnerability scanner that checks for known dangerous files, outdated server software, and misconfigurations by matching responses against a large database of vulnerability signatures. It does not perform wordlist-based brute-forcing to reveal hidden API endpoints or undocumented directories; its focus is identifying known weaknesses rather than exploratory content discovery. Because the goal is finding endpoints rather than vulnerabilities, Nikto is not applicable here.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.