PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, you find a web application that uses JavaScript to make API calls. You want to discover hidden API endpoints and potential secrets (e.g., API keys) embedded in the client-side code. Which approach is most appropriate?
⚠ Common exam trap
Test-takers frequently confuse information gathering techniques (e.g., DNS zone transfer or OSINT) with client-side code analysis, assuming that API endpoints must be found through network scanning rather than by examining the application's own source code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Download and analyze the JavaScript files
JavaScript files in client-side web applications often contain hardcoded API endpoints, API keys, and other secrets that developers inadvertently leave in the source code. By downloading and analyzing these files (e.g., via browser developer tools or wget), you can discover hidden endpoints and sensitive tokens that are not exposed in the HTML or network traffic alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Download and analyze the JavaScript files
Why this is correct
Downloading and analyzing the JavaScript files is the correct approach because client-side web applications commonly expose API endpoints, authentication logic, and hardcoded secrets within their scripts. By fetching every .js file referenced by the page (including bundled and lazy-loaded modules), you can inspect source maps, search for strings like 'api/', 'token', 'secret', or 'Bearer', and reconstruct the application's internal routing. Tools like Burp Suite, Chrome DevTools, and JSParser can automate extraction, and even minified code can be beautified to reveal hidden functionality that is not visible in normal page interaction.
- ✗
Perform a DNS zone transfer
Why it's wrong here
A DNS zone transfer is a technique used against DNS servers to request a full copy of a zone's resource records, such as A, MX, and NS records, but it has no bearing on the client-side JavaScript running in a web application. While a successful AXFR can reveal internal hostnames and network architecture, it cannot expose API endpoints, keys, or logic embedded in the application's code. This option is wrong because it targets infrastructure DNS, not the web client's static resources, and would likely be part of passive reconnaissance, not JavaScript analysis.
- ✗
Run a Nikto scan against the application
Why it's wrong here
Nikto is an open-source web server scanner that checks for known vulnerabilities, insecure files, outdated server software, and dangerous misconfigurations; it sends crafted HTTP requests to the server and inspects response headers and content. It does not execute or parse JavaScript in the browser context, so it cannot discover dynamically defined API routes or hardcoded secrets that only appear after the client-side script runs. Running Nikto would be a useful complementary step during a comprehensive assessment, but it is not the correct method for analyzing JavaScript files to extract endpoints and credentials.
- ✗
Use theHarvester to search for API endpoints
Why it's wrong here
theHarvester is an OSINT tool designed to gather email addresses, employee names, subdomains, and hostnames from public sources like search engines, PGP key servers, and shodan, but it does not interact with the target web application's JavaScript. It performs passive reconnaissance across the internet, not client-side code analysis, and its output is limited to publicly indexed metadata, not API endpoints or secrets hardcoded into a live application's scripts. Using theHarvester here would be a misunderstanding of its role; it is a data collection tool, not a JavaScript parser or endpoint extractor.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.