PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing active reconnaissance on a target web application. Which TWO tools are specifically designed for directory and file enumeration? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Feroxbuster
Gobuster and Feroxbuster are both tools specifically designed for directory and file brute-forcing on web servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wappalyzer
Why it's wrong here
Wappalyzer is a browser extension and technology fingerprinting tool that identifies web frameworks, CMS platforms, and JavaScript libraries by analyzing HTTP headers, cookies, and page source. It performs passive or semi-passive inspection but does not actively send crafted requests to enumerate hidden directories or files. Therefore, it cannot discover unlinked paths or sensitive resources, making it unsuitable for directory brute-forcing during active reconnaissance.
- ✓
Feroxbuster
Why this is correct
Feroxbuster is a Rust-based recursive content discovery tool specifically engineered for fast directory and file brute-forcing. It supports wordlist-driven scanning, multiple file extensions, recursion, and automatic filtering of irrelevant status codes and response sizes, allowing penetration testers to efficiently map out hidden web resources. Its speed and recursive crawling make it an excellent choice for active reconnaissance on web applications.
- ✗
Nmap
Why it's wrong here
Nmap is primarily a network scanning utility used for host discovery, port scanning, service version detection, and OS fingerprinting via raw packets. While it has NSE scripts like http-enum that can probe HTTP endpoints, it is not optimized for comprehensive web directory enumeration, and its scripts are generally slower and less thorough than purpose-built directory busters. Using Nmap alone for hidden path discovery would overlook many resources that a dedicated content discovery tool would find.
- ✓
Gobuster
Why this is correct
Gobuster is a multi-purpose brute-force tool written in Go that excels at directory and file enumeration using wordlists, and it also supports DNS subdomain and virtual host discovery. It sends rapid, concurrent HTTP requests and relies on response status codes to identify valid paths, making it a fast and reliable choice for active reconnaissance. Its simplicity and ability to be integrated into scripting workflows make it a popular alternative to Feroxbuster for web content discovery.
- ✗
WhatWeb
Why it's wrong here
WhatWeb is a web fingerprinting scanner that identifies technologies used on a site by matching signatures against HTTP responses, HTML structure, and headers. It can tell you that a target runs WordPress, Apache, or jQuery, but it does not actively probe for hidden files, directories, or backup archives. Since it lacks brute-forcing capabilities, it cannot enumerate unlinked endpoints and is therefore not suited for directory discovery.
Go deeper
Related to this question
Learn chapter
Command Injection and Directory Traversal
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.