Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, the tester is using Gobuster to enumerate directories on a web server. Which flag would the tester use to specify a list of file extensions to append to each word in the wordlist for discovering files like 'admin.php' or 'config.bak'?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-x

The -x flag in Gobuster allows specifying extensions to append to each word during directory/file bruteforcing, enabling discovery of files with those extensions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -e

    Why it's wrong here

    -e is the expanded-mode flag for Gobuster. When combined with a mode such as dir or vhost, it forces the tool to print the full URL path in each result rather than just the discovered directory or file name. This does not append file extensions or alter the request target; it only changes output verbosity. Thus, while useful for readability in reports, -e has no role in making Gobuster find backup files like config.php.bak.

  • ✓

    -x

    Why this is correct

    -x is the correct flag for this scenario because it appends a comma-separated list of file extensions to each word from the wordlist when fuzzing directories. For example, using -x php,bak makes Gobuster test each word as-is, then with .php appended, and then with .bak appended, which is exactly how a tester discovers hidden backup files such as index.php.bak. Without this flag, Gobuster only requests the literal word paths, missing extension-based files entirely. This is why -x is the right answer for enumerating files with specific suffixes.

  • ✗

    -w

    Why it's wrong here

    -w is the flag that specifies the path to the wordlist file containing the base directory or file names to brute-force. It does not control which file suffixes are tested; rather, it simply provides the list of candidate names that Gobuster will substitute into the URL. If a tester needs to find backup files, the wordlist must contain names like config or index, but the extension discovery requires the -x flag to append .bak or other suffixes. Therefore, -w is necessary but not sufficient for the stated task, making it the wrong single-flag answer.

  • ✗

    -t

    Why it's wrong here

    -t sets the number of concurrent threads or goroutines Gobuster uses to send HTTP requests. Increasing -t speeds up the brute-force process by creating more parallel connections, but it has zero effect on the set of paths being tested or on file extension handling. A tester might use -t 50 to make enumeration faster, yet without -x the tool still will not probe for .bak or .php files. Hence, -t is a performance-tuning option, not a functional option for discovering backup files with specific extensions.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.