PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, a tester discovers a web application that uses JavaScript to load API endpoints dynamically. Which technique would be most effective for discovering hidden API endpoints?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyzing JavaScript files for API endpoints
JavaScript analysis involves inspecting JavaScript files for hardcoded API endpoints, secrets, and other useful information, making it effective for discovering hidden API endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyzing JavaScript files for API endpoints
Why this is correct
Analyzing JavaScript files is the definitive technique here because modern single-page applications bundle most of their client-side logic into JavaScript. Static analysis of the code (or dynamic inspection via browser DevTools' Network tab) can reveal backend API URLs, request parameters, authentication tokens, and webpack chunk references that are never publicly documented. Source maps, if left exposed, can even reconstruct the original source to expose hidden or internal endpoints that network scanners cannot see.
- ✗
Performing a DNS zone transfer
Why it's wrong here
A DNS zone transfer (AXFR/IXFR) only copies the DNS zone database records, including A, AAAA, MX, TXT, and NS records, which map domain names to IP addresses and mail servers. It cannot reveal API endpoints because those are paths and parameters within HTTP requests that live in the application layer, not in DNS. Even if misconfigured DNS servers allow zone transfers, the acquired hostnames are useful for network inventory, not for discovering JavaScript-based API routes.
- ✗
Running a Nikto scan
Why it's wrong here
Nikto is an active web server vulnerability scanner that probes for known dangerous files (e.g., default CGI scripts, outdated server software, and common misconfigurations) by sending crafted HTTP requests. It does not parse, execute, or analyze client-side JavaScript content, so it cannot enumerate API endpoints embedded inside script files. While Nikto might coincidentally detect a JS file path, it provides no insight into the API routes, parameters, or tokens that the code actually uses.
- ✗
Using Nmap to scan for open ports and services
Why it's wrong here
Nmap performs network-level discovery by sending raw packets to identify open TCP/UDP ports, running services, and operating system versions through banner grabbing and script scanning. It is completely blind to the contents of HTTP response bodies, including JavaScript files, so it cannot extract API URLs or endpoints from them. Nmap is useful for determining that a web server is on port 80/443, but endpoint discovery happens at the application layer, requiring HTTP-specific analysis of the rendered client code.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.