mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a web…
A penetration tester is analyzing a web application's JavaScript files to discover hidden API endpoints and potential client-side vulnerabilities. Which tool is specifically designed to extract URLs and endpoints from JavaScript files?
⚠ Common exam trap
A common mix-up: candidates confuse network analysis tools (Wireshark) or general-purpose scanners (Nmap) with specialized JavaScript endpoint extractors, or assume Burp Suite's scope management is a discovery tool rather than a filtering mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LinkFinder
LinkFinder is a Python-based tool specifically designed to extract URLs and endpoints from JavaScript files by using regular expressions and parsing techniques. It analyzes JS files for patterns like API routes, relative paths, and hardcoded URLs, making it ideal for discovering hidden endpoints during web application penetration testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures packets at the link and transport layers, inspecting raw traffic rather than application-layer content. While it can reassemble HTTP streams and export transferred files, it does not parse JavaScript source code to enumerate endpoint URLs, requiring manual stream inspection and regex filtering that make this approach impractical. As a result, it is not suited for directly discovering API routes embedded in client-side scripts.
- ✗
Burp Suite's Target scope
Why it's wrong here
Burp Suite's Target scope is a configuration setting that restricts the proxy, spider, and scanner to specific hosts or IP ranges, not a JavaScript analysis feature. Although the built-in Spider can discover some links by parsing HTML and following script tags, it does not systematically deep-parse JavaScript files to exhaustively extract endpoints. To efficiently mine JS for hidden API routes, you would need an extension like JS Link Finder or a separate dedicated tool, so Target scope alone is not the correct answer.
- ✓
LinkFinder
Why this is correct
LinkFinder is a dedicated open-source Python tool designed specifically for parsing JavaScript files and extracting URLs, paths, and fully qualified endpoints using regex patterns and lightweight parsing. It accepts a URL, local file, or Burp session data and outputs both relative and absolute links, making it purpose-built for this exact reconnaissance task. This is why it is the correct answer when analyzing a web application's JavaScript to locate endpoints.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanner that sends crafted packets to discover hosts, open ports, and running services, and it fingerprints operating systems by examining TCP/IP stack behavior. Its NSE scripting engine focuses on network-level and protocol-specific vulnerabilities, not on parsing HTTP response bodies or JavaScript source code, so it cannot reveal endpoints stored in client-side scripts. Therefore, Nmap is fundamentally misaligned with the objective of analyzing a web application's JavaScript content.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.