Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is assessing a web application and wants to identify hidden parameters that the application accepts. Which tool is specifically designed for parameter discovery?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Arjun

Arjun is a tool for discovering HTTP parameters by brute-forcing common parameter names and analyzing responses for changes, making it suitable for parameter discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is specifically engineered for WordPress targets, enumerating the core version, installed plugins, and themes, then matching them against vulnerability databases. It does not perform generic parameter fuzzing; its primary goal is fingerprinting WordPress and checking for known CVEs, not discovering unhandled or hidden request parameters that could alter application logic. Thus, it would miss non-WordPress applications entirely.

  • ✓

    Arjun

    Why this is correct

    Arjun is a purpose-built tool for discovering hidden GET and POST parameters. It sends requests containing candidate parameter names from a large wordlist and uses response-differential analysis—comparing status codes, response size, and reflected content—to determine whether a parameter affects the server's response. Crucially, it has heuristics for 'reflect' detection, where the parameter name or value appears in the response, a strong signal of parameter existence. This makes it ideal for finding custom parameters not advertised in the UI or API documentation.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a long-standing web server scanner that checks for outdated server software, dangerous files, and common misconfigurations like default credentials or exposed 'admin' paths. It operates on a static database of known vulnerabilities and server signatures, and it does not generate dynamic requests to fuzz for arbitrary parameters. Though it can identify some 'interesting' files, it does not perform parameter enumeration at the application layer, making it unsuitable for this task.

  • ✗

    Gobuster

    Why it's wrong here

    Gobuster is a high-speed brute-forcing tool commonly used to discover directory paths, filenames, virtual hosts, and DNS subdomains by iterating a wordlist and observing response status codes. Its output is a list of reachable URLs for a given web root, not a set of request parameters that the application expects. Since it operates on URL paths rather than on the query string or POST body, it cannot reveal hidden parameters like 'user_id' or 'debug' that the application might process.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.