Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing web application reconnaissance and wants to discover API endpoints and hidden parameters that may not be linked from the main application. Which technique would be most effective for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JavaScript analysis for endpoint discovery

JavaScript analysis often reveals AJAX API endpoints, keys, and parameters that are not visible in HTML. Directory bruteforcing may find endpoints but JS analysis is more targeted for hidden APIs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running Nikto for web server vulnerabilities

    Why it's wrong here

    Nikto is a legacy web server scanner that sends a battery of predefined HTTP requests to identify outdated software, dangerous CGI files, and server misconfigurations. It does not parse JavaScript bundles or follow client-side application logic, so it cannot reveal API endpoints that are only defined as string literals or fetch calls. This makes it unsuitable for endpoint discovery, as its focus is purely on server-side vulnerability fingerprinting.

  • ✓

    JavaScript analysis for endpoint discovery

    Why this is correct

    JavaScript analysis is the correct approach because modern single-page applications often hard-code the API surface in their client-side code, such as REST URLs, GraphQL operation names, and route parameters. By examining network calls (fetch, XHR, WebSocket) and string literals, you can uncover undocumented endpoints that are not linked anywhere else in the HTML or robots.txt. This directly expands the attack surface and is a core web app recon technique.

  • ✗

    Directory bruteforcing with gobuster

    Why it's wrong here

    Directory brute-forcing with gobuster makes thousands of HTTP requests based on a wordlist to identify existing paths, but it only finds resources that are directly accessible and return a distinct status code. Endpoints that are only referenced inside JavaScript are invisible to this method because they are not discovered through file-system enumeration. Additionally, it is noisy, may be blocked by rate limiting, and often misses non-standard API routes that require special headers or parameters.

  • ✗

    Using Wappalyzer to fingerprint technologies

    Why it's wrong here

    Wappalyzer infers the underlying technology stack by inspecting HTTP response headers, HTML meta tags, and JavaScript global identifiers, such as detecting React, Django, or jQuery. This is useful for selecting known exploits, but it provides no visibility into the specific URI structure, API endpoints, or routing tables of the application. It can tell you what framework is running, not which resources are exposed through that framework.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.