PT0-002 Reconnaissance and Enumeration Practice Question
A tester wants to identify the technologies used by a web application before conducting a deeper assessment. Which tool would be most appropriate for passive technology fingerprinting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wappalyzer
Wappalyzer is a browser extension or online tool that identifies web technologies (CMS, frameworks, analytics) by analyzing page content and headers without sending probes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap is an active reconnaissance tool that sends crafted IP packets, such as TCP SYN scans and service probe requests, to target hosts to elicit responses. Its version detection feature (e.g., -sV) actively connects to open ports and exchanges data with the service to fingerprint it, which is fundamentally intrusive. Because it initiates network traffic rather than passively observing existing traffic, it does not meet the requirement of passive technology identification.
- ✓
Wappalyzer
Why this is correct
Wappalyzer is a browser extension and library that performs passive technology fingerprinting by inspecting HTTP response headers (e.g., X-Powered-By, Set-Cookie), HTML meta tags, script sources, and other client-side content returned by the web application. It does not send a single request to the target beyond what the browser itself makes, so it identifies frameworks, CMSs, analytics tools, and server software entirely from normal page loads. This makes it the correct tool for passive identification in this scenario.
- ✗
OpenVAS
Why it's wrong here
OpenVAS is a full-featured active vulnerability scanner, not a passive technology identifier. It transmits a large volume of proprietary NASL-based probes, including exploit payloads and configuration checks, to a target to detect CVEs and misconfigurations. Even when configured for 'stealth,' it actively interacts with the application and generates traffic, which would alter the target's state and potentially trigger defenses, making it unsuitable for passive reconnaissance.
- ✗
Nikto
Why it's wrong here
Nikto is an aggressive web server scanner that sends thousands of crafted HTTP requests—such as paths for known files, dangerous scripts, and injection strings—to uncover vulnerabilities and outdated software. It relies on active responses to build its findings, and its signature-based checks often attempt to retrieve specific files or trigger error pages. Therefore, it cannot be used for passive technology identification since it does not simply observe existing traffic and instead actively probes the web application.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.