Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden API endpoints. Which TWO tools are BEST suited for this task? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Feroxbuster

Gobuster can be used to bruteforce directories and files, including API paths. Feroxbuster is a similar tool written in Rust that is faster and supports recursion. Both are effective for API endpoint discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wappalyzer

    Why it's wrong here

    Wappalyzer is a browser extension and website profiler that fingerprints frameworks, CMSs, analytics, and other client- or server-side technologies by inspecting HTTP responses, HTML, and JavaScript. Although it can reveal an API's underlying stack (e.g., Express, Django), it does not enumerate routes, endpoints, or hidden resources. Active reconnaissance for API discovery requires sending crafted requests to discover paths, which Wappalyzer does not do.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web vulnerability scanner that checks for outdated server software, dangerous files, and common misconfigurations against a large database of signatures. It can find some default or exposed files, but it is not optimized for API endpoint enumeration; it lacks the wordlist-driven brute-forcing of directory structures that tools like Feroxbuster or Gobuster provide. Using Nikto for active API reconnaissance would miss most RESTful routes and produce noisy, HTTP-heavy output without targeted endpoint discovery.

  • ✗

    theHarvester

    Why it's wrong here

    theHarvester is an OSINT tool that gathers emails, subdomains, hosts, and employee names from public sources like search engines, PGP key servers, and SHODAN. It performs passive or semi-passive reconnaissance and does not interact with the target's web application to identify API endpoints. While its subdomain results might indirectly reveal API hosts, it cannot brute-force or enumerate the actual REST paths, making it unsuitable for active API discovery.

  • ✓

    Feroxbuster

    Why this is correct

    Feroxbuster is a fast, recursive content discovery tool written in Rust that uses brute-forcing with a wordlist to find directories and files on web servers. It is specifically effective for API discovery because it supports recursion, file extensions, status-code filtering, and concurrent requests, allowing a tester to uncover hidden REST endpoints such as /api/v1/users or /admin. Its performance and flexibility make it a top choice for active reconnaissance against web APIs.

  • ✓

    Gobuster

    Why this is correct

    Gobuster is a versatile brute-forcing tool that can enumerate directories, files, DNS subdomains, and virtual hosts using wordlists. For API discovery, it can be used in directory mode to find endpoint paths, though it is typically less feature-rich than Feroxbuster regarding recursion and filtering. Still, it is a valid correct answer because it actively brute-forces URL paths to reveal hidden API routes.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.