Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?

⚠ Common exam trap

PT0-003 often tests tool specialization; candidates may pick Gobuster and Nikto because they are well-known web tools, but they are not optimized for hidden parameter discovery, which is the specific task in the question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Arjun and ffuf

Arjun is a specialized tool for discovering hidden HTTP parameters by fuzzing with a wordlist and analyzing responses, while ffuf is a fast web fuzzer used for directory, file, and parameter discovery. Together, they efficiently uncover API endpoints and hidden parameters that are not linked in the application's visible interface. This combination is specifically designed for the reconnaissance phase of API testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wappalyzer and curl

    Why it's wrong here

    Wappalyzer identifies client-side frameworks and curl manually requests known URLs; neither brute-forces directories nor fuzzes parameter names. This pairing suits confirming a detected technology stack or replaying a specific request, not discovering undocumented endpoints and hidden parameters.

  • ✗

    WhatWeb and theHarvester

    Why it's wrong here

    WhatWeb fingerprints web technologies and theHarvester gathers OSINT email addresses and subdomains; neither enumerates API routes or fuzzes parameters. The pairing suits reconnaissance of an organisation's external footprint, not endpoint discovery within a live application.

  • ✗

    Gobuster and Nikto

    Why it's wrong here

    Gobuster brute-forces directories and DNS, while Nikto scans for known server misconfigurations and outdated software; neither fuzzes API parameter names. The pairing suits broad web server vulnerability scanning, not enumerating REST or GraphQL endpoints and their accepted parameters.

  • ✓

    Arjun and ffuf

    Why this is correct

    Arjun discovers hidden API parameters and endpoints through its extensive wordlists and passive/active scanning, while ffuf fuzzes directories, parameters and virtual hosts at high speed. Together they satisfy the stem's need to uncover endpoints and hidden parameters in a web application.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.