PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, a tester uses the Wayback Machine to review historical versions of the target's website. What is the primary benefit of this activity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It reveals old web pages that may contain sensitive information or forgotten endpoints
The Wayback Machine archives historical snapshots of web pages, which can reveal old files, endpoints, or sensitive information that may have been removed but are still accessible on the live site.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It reveals old web pages that may contain sensitive information or forgotten endpoints
Why this is correct
Historical snapshots stored by the Internet Archive capture the target's web pages at various points in time. Penetration testers can mine these archives to locate old URLs, deprecated backup files, configuration snippets, or even credentials that were inadvertently posted before being removed from the live site. This passive intelligence gathering expands the attack surface by exposing forgotten endpoints that no longer appear in current site maps.
- ✗
It bypasses the target's WAF
Why it's wrong here
A web application firewall (WAF) filters inbound traffic to a live server, whereas the Wayback Machine simply serves cached copies of a site from a third-party repository. Since the archive never sends requests to the target's production infrastructure, it cannot trigger, test, or circumvent WAF rules. Bypassing a WAF requires direct interaction with the live endpoint and custom payloads designed to evade specific filtering logic.
- ✗
It provides real-time vulnerability data
Why it's wrong here
The Wayback Machine's snapshots are historical and asynchronous, often months or years old, so they reflect the site's state at crawl time rather than its current security posture. Real-time vulnerability data demands live response analysis, port scanning, or service version matching, none of which an archive can provide. Even if a snapshot reveals an old vulnerability, it does not confirm the flaw persists in the present.
- ✗
It performs a live vulnerability scan
Why it's wrong here
The Wayback Machine is a purely passive repository that stores static HTML, images, and assets; it does not execute JavaScript, send dynamic requests, or interact with application logic. Live vulnerability scans rely on sending crafted probes to the target, analyzing responses, and validating findings — functionality that an archival service fundamentally lacks. Consequently, it can never perform a scan or identify exploitable weaknesses on its own.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.