PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting a web application reconnaissance and wants to discover API endpoints and hidden parameters. Which three tools are most appropriate for this task? (Choose THREE.)
⚠ Common exam trap
Test-takers frequently confuse technology fingerprinting tools (Wappalyzer, Whatweb) with active discovery tools, or forget that Gobuster's directory brute-force mode is valid for API endpoint discovery, not just web directories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ffuf
ffuf (A) is correct because it is a fast web fuzzer that can brute-force directories, files, and API endpoint paths using wordlists, making it ideal for discovering hidden API routes. Arjun (C) is correct because it is specifically designed to discover hidden HTTP parameters by sending requests with common parameter names and analyzing response differences, which directly addresses the hidden-parameter discovery goal. Gobuster (D) is correct because its dir and vhost modes perform dictionary-based brute-forcing of web paths and subdomains, effectively enumerating API endpoints and hidden directories. Wappalyzer (B) is not appropriate because it only fingerprints technologies (CMS, frameworks, libraries) from page content and headers, not endpoints or parameters. Whatweb (E) is also a fingerprinting tool that identifies web technologies and server banners, so it does not enumerate endpoints or hidden parameters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ffuf
Why this is correct
ffuf brute-forces web paths and parameter names using wordlists, directly satisfying the requirement to discover hidden API endpoints and parameters during reconnaissance. Its fuzzing engine substitutes payloads into URL paths or query strings, revealing resources that normal browsing misses, making it appropriate alongside other content-discovery tools.
- ✗
Wappalyzer
Why it's wrong here
Wappalyzer identifies the technology stack behind a site — frameworks, analytics and CMS — from page markers; it performs no endpoint or parameter enumeration. Discovering hidden API routes and parameters requires wordlist-driven fuzzing or spidering, as with ffuf, Gobuster or Burp Suite. Wappalyzer is correct when fingerprinting technologies during reconnaissance.
- ✓
Arjun
Why this is correct
Arjun performs dictionary-based HTTP parameter discovery, brute-forcing hidden GET and POST parameters against a target URL. This directly satisfies the requirement to uncover hidden parameters during web application reconnaissance, complementing endpoint discovery tools by enumerating the parameter names that other scanners overlook.
- ✓
Gobuster
Why this is correct
Gobuster performs brute-force enumeration of web paths, directories and DNS subdomains using wordlists, directly satisfying the requirement to discover API endpoints and hidden parameters. Its `dir` and `vhost` modes systematically reveal unlinked resources that manual browsing misses, making it appropriate for this reconnaissance task.
- ✗
Whatweb
Why it's wrong here
Whatweb fingerprints web servers, CMS platforms and JavaScript libraries from response headers and page content; it does not enumerate API endpoints or brute-force hidden parameters. Endpoint and parameter discovery needs tools such as ffuf, Gobuster or Burp Suite's content discovery. Whatweb fits technology-stack identification during initial reconnaissance.
Go deeper
Related to this question
Learn chapter
Web Fuzzing: Dirbusting and Parameter Discovery
Key term
Fingerprinting
Fingerprinting is the process of gathering information about a target system or network to identify its operating system, services, software versions, and configuration details during the reconnaissance phase of a security assessment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.