PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is assessing a web application and wants to identify hidden parameters that the application accepts. Which tool is specifically designed for parameter discovery?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Arjun
Arjun is a tool for discovering HTTP parameters by brute-forcing common parameter names and analyzing responses for changes, making it suitable for parameter discovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPScan
Why it's wrong here
WPScan is specifically engineered for WordPress targets, enumerating the core version, installed plugins, and themes, then matching them against vulnerability databases. It does not perform generic parameter fuzzing; its primary goal is fingerprinting WordPress and checking for known CVEs, not discovering unhandled or hidden request parameters that could alter application logic. Thus, it would miss non-WordPress applications entirely.
- ✓
Arjun
Why this is correct
Arjun is a purpose-built tool for discovering hidden GET and POST parameters. It sends requests containing candidate parameter names from a large wordlist and uses response-differential analysis—comparing status codes, response size, and reflected content—to determine whether a parameter affects the server's response. Crucially, it has heuristics for 'reflect' detection, where the parameter name or value appears in the response, a strong signal of parameter existence. This makes it ideal for finding custom parameters not advertised in the UI or API documentation.
- ✗
Nikto
Why it's wrong here
Nikto is a long-standing web server scanner that checks for outdated server software, dangerous files, and common misconfigurations like default credentials or exposed 'admin' paths. It operates on a static database of known vulnerabilities and server signatures, and it does not generate dynamic requests to fuzz for arbitrary parameters. Though it can identify some 'interesting' files, it does not perform parameter enumeration at the application layer, making it unsuitable for this task.
- ✗
Gobuster
Why it's wrong here
Gobuster is a high-speed brute-forcing tool commonly used to discover directory paths, filenames, virtual hosts, and DNS subdomains by iterating a wordlist and observing response status codes. Its output is a list of reachable URLs for a given web root, not a set of request parameters that the application expects. Since it operates on URL paths rather than on the query string or POST body, it cannot reveal hidden parameters like 'user_id' or 'debug' that the application might process.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.