Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is analyzing a web application's JavaScript files for hardcoded secrets and API endpoints. Which THREE techniques or tools are MOST effective for this purpose? (Select THREE.)

⚠ Common exam trap

The exam often tests the distinction between tools that passively extract information from existing files (LinkFinder, SecretFinder) versus tools that actively bruteforce or fingerprint server-side resources (Gobuster, Wappalyzer), leading candidates to select tools that serve different phases of the penetration test.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using LinkFinder to extract endpoints from JavaScript

LinkFinder (A) is correct because it parses JavaScript files with regex patterns to extract URL paths, endpoints, and parameters that are otherwise buried in minified or bundled code, directly serving the goal of discovering API endpoints. SecretFinder (C) is correct because it is built specifically to scan JavaScript for high-entropy strings and regex signatures matching API keys, tokens, and other hardcoded secrets. Manually examining JavaScript source files (E) is correct because human review catches context-dependent secrets, obfuscated logic, and endpoint patterns that automated regex tools may miss or misclassify. Wappalyzer (B) is not appropriate here because it only fingerprints technologies and frameworks from headers and page artifacts, not secrets or endpoints inside JS. Gobuster (D) is not appropriate because it performs directory and file brute-forcing against the web server, which does not analyze JavaScript content for secrets or embedded endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using LinkFinder to extract endpoints from JavaScript

    Why this is correct

    LinkFinder parses JavaScript files with regular expressions to extract URL paths, relative endpoints and API routes embedded in client-side code, directly satisfying the requirement to enumerate endpoints. Unlike generic secret scanners, it targets endpoint discovery specifically, making it effective when reviewing minified or bundled JavaScript for hidden API surfaces.

  • ✗

    Using Wappalyzer to identify frameworks

    Why it's wrong here

    Wappalyzer fingerprints server-side frameworks and libraries from HTTP headers and page markup; it cannot read JavaScript file contents, so it never surfaces hardcoded secrets or embedded API endpoints. It would be the right choice when enumerating the technology stack during reconnaissance, not when mining JS source.

  • ✓

    Using SecretFinder to search for API keys and secrets

    Why this is correct

    SecretFinder parses JavaScript files and applies entropy analysis plus regex patterns to detect exposed API keys, tokens and secrets, directly satisfying the stem's requirement to find hardcoded credentials within client-side code. It targets the exact artefact under analysis rather than network traffic or compiled binaries, making it one of the three most effective techniques.

  • ✗

    Using Gobuster to bruteforce directories

    Why it's wrong here

    Gobuster brute-forces directory and file paths on the web server, returning HTTP status codes; it does not parse JavaScript contents, so hardcoded secrets and API endpoints stay hidden. It would be the right choice for discovering unlinked directories or backup files, not for static analysis of JS.

  • ✓

    Manually examining JavaScript source files

    Why this is correct

    Manually reading the JavaScript source exposes hardcoded secrets and endpoint paths that automated scanners may miss, particularly when values are split across variables or obfuscated. This directly satisfies the stem's requirement to analyse client-side files for concealed credentials and API routes, complementing tooling with human pattern recognition.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.