Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, a tester discovers a web application that uses JavaScript to load API endpoints dynamically. Which technique would be most effective for discovering hidden API endpoints?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyzing JavaScript files for API endpoints

JavaScript analysis involves inspecting JavaScript files for hardcoded API endpoints, secrets, and other useful information, making it effective for discovering hidden API endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analyzing JavaScript files for API endpoints

    Why this is correct

    Analyzing JavaScript files is the definitive technique here because modern single-page applications bundle most of their client-side logic into JavaScript. Static analysis of the code (or dynamic inspection via browser DevTools' Network tab) can reveal backend API URLs, request parameters, authentication tokens, and webpack chunk references that are never publicly documented. Source maps, if left exposed, can even reconstruct the original source to expose hidden or internal endpoints that network scanners cannot see.

  • ✗

    Performing a DNS zone transfer

    Why it's wrong here

    A DNS zone transfer (AXFR/IXFR) only copies the DNS zone database records, including A, AAAA, MX, TXT, and NS records, which map domain names to IP addresses and mail servers. It cannot reveal API endpoints because those are paths and parameters within HTTP requests that live in the application layer, not in DNS. Even if misconfigured DNS servers allow zone transfers, the acquired hostnames are useful for network inventory, not for discovering JavaScript-based API routes.

  • ✗

    Running a Nikto scan

    Why it's wrong here

    Nikto is an active web server vulnerability scanner that probes for known dangerous files (e.g., default CGI scripts, outdated server software, and common misconfigurations) by sending crafted HTTP requests. It does not parse, execute, or analyze client-side JavaScript content, so it cannot enumerate API endpoints embedded inside script files. While Nikto might coincidentally detect a JS file path, it provides no insight into the API routes, parameters, or tokens that the code actually uses.

  • ✗

    Using Nmap to scan for open ports and services

    Why it's wrong here

    Nmap performs network-level discovery by sending raw packets to identify open TCP/UDP ports, running services, and operating system versions through banner grabbing and script scanning. It is completely blind to the contents of HTTP response bodies, including JavaScript files, so it cannot extract API URLs or endpoints from them. Nmap is useful for determining that a web server is on port 80/443, but endpoint discovery happens at the application layer, requiring HTTP-specific analysis of the rendered client code.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.