Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is assessing a web application and wants to discover hidden directories, files, and parameters. Which THREE of the following tools are most appropriate for this task?

⚠ Common exam trap

Watch out — candidates often confuse vulnerability scanners (Nikto) or technology fingerprinters (Wappalyzer) with directory brute-forcing tools, leading them to select options that serve different phases of the penetration testing methodology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dirsearch

dirsearch (B) is a Python-based web path scanner that brute-forces directories and files using wordlists and supports extensions, recursion, and custom headers, making it ideal for discovering hidden content. feroxbuster (D) is a fast Rust-based content discovery tool that performs recursive directory brute-forcing with wordlists and can also fuzz parameters, directly matching the task. Gobuster (E) is a Go-based tool whose dir and vhost modes enumerate hidden directories/files (and DNS subdomains) via wordlist brute-forcing, which is exactly the required discovery activity. Nikto (A) is a web server vulnerability scanner that checks for misconfigurations and known issues rather than brute-forcing hidden paths, Wappalyzer (C) is a technology fingerprinting tool that identifies CMS, frameworks, and libraries from page content, and neither is designed for directory/file/parameter brute-force discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web server vulnerability scanner that identifies known security issues, outdated software, and misconfigurations by comparing responses against a large database of test signatures. While it may check for a handful of default filenames, it does not systematically brute-force directory names or fuzz for hidden paths. Its primary purpose is vulnerability assessment, not content discovery, so it is the wrong tool for this task.

  • ✓

    dirsearch

    Why this is correct

    Dirsearch is an open-source, Python-based command-line tool explicitly built for directory brute-forcing and content discovery. It takes a wordlist of candidate path names, sends HTTP requests for each, and identifies valid resources by analyzing response status codes, sizes, and redirects. It supports recursive scanning, multi-threading, custom HTTP methods, and filters, making it a direct and effective answer to discovering hidden web paths.

  • ✗

    Wappalyzer

    Why it's wrong here

    Wappalyzer is a browser extension and online service that passively identifies web technologies—such as frameworks, CMSs, analytics tools, and server software—by inspecting HTTP headers, cookies, and page content. It does not actively send requests to enumerate directory names or probe for unlinked files. Since it only examines what is already presented by the application, it cannot uncover hidden paths and is therefore incorrect here.

  • ✓

    feroxbuster

    Why this is correct

    Feroxbuster is a high-performance, Rust-based recursive content discovery tool designed specifically for brute-forcing web directories and files. It uses a wordlist to send HTTP requests to a target, then reports valid paths based on response codes and content length, with built-in support for recursion and wildcard detection. Its speed and low false-positive handling make it a strong choice for directory enumeration, so it is a correct tool for this scenario.

  • ✓

    Gobuster

    Why this is correct

    Gobuster is a fast content discovery tool written in Go that includes a dedicated mode for brute-forcing directories and files on web servers using a wordlist. It sends HTTP requests for each candidate path and converts meaningful responses (e.g., 200, 301, 403) into a list of discovered resources. While it also supports DNS subdomain and virtual host enumeration, its directory mode makes it perfectly suitable for the penetration tester's objective.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.