PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?
⚠ Common exam trap
PT0-003 often tests tool specialization; candidates may pick Gobuster and Nikto because they are well-known web tools, but they are not optimized for hidden parameter discovery, which is the specific task in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Arjun and ffuf
Arjun is a specialized tool for discovering hidden HTTP parameters by fuzzing with a wordlist and analyzing responses, while ffuf is a fast web fuzzer used for directory, file, and parameter discovery. Together, they efficiently uncover API endpoints and hidden parameters that are not linked in the application's visible interface. This combination is specifically designed for the reconnaissance phase of API testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wappalyzer and curl
Why it's wrong here
Wappalyzer identifies client-side frameworks and curl manually requests known URLs; neither brute-forces directories nor fuzzes parameter names. This pairing suits confirming a detected technology stack or replaying a specific request, not discovering undocumented endpoints and hidden parameters.
- ✗
WhatWeb and theHarvester
Why it's wrong here
WhatWeb fingerprints web technologies and theHarvester gathers OSINT email addresses and subdomains; neither enumerates API routes or fuzzes parameters. The pairing suits reconnaissance of an organisation's external footprint, not endpoint discovery within a live application.
- ✗
Gobuster and Nikto
Why it's wrong here
Gobuster brute-forces directories and DNS, while Nikto scans for known server misconfigurations and outdated software; neither fuzzes API parameter names. The pairing suits broad web server vulnerability scanning, not enumerating REST or GraphQL endpoints and their accepted parameters.
- ✓
Arjun and ffuf
Why this is correct
Arjun discovers hidden API parameters and endpoints through its extensive wordlists and passive/active scanning, while ffuf fuzzes directories, parameters and virtual hosts at high speed. Together they satisfy the stem's need to uncover endpoints and hidden parameters in a web application.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.