PT0-002 Reconnaissance and Enumeration Practice Question
During a web application penetration test, the tester wants to identify the technologies used by the target website. Which of the following tools is best suited for technology fingerprinting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WhatWeb
WhatWeb (option D) is the correct choice because it is a dedicated web technology fingerprinting tool that identifies CMS platforms, JavaScript libraries, web servers, and frameworks by analyzing HTTP responses, headers, meta tags, and file signatures. In a web application penetration test, this directly addresses the goal of enumerating the technologies behind the target site. Nikto (A) is a web server vulnerability scanner, not a technology fingerprinter, though it may incidentally reveal some server details. Nmap (B) is a network/host discovery and port scanning tool with limited HTTP fingerprinting via NSE scripts, and Gobuster (C) is a directory and DNS brute-forcing tool, neither of which is purpose-built for identifying web technologies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nikto
Why it's wrong here
Nikto is a web server scanner that primarily checks for known vulnerabilities, dangerous files, and outdated server software by sending crafted HTTP requests and matching responses against a database of configuration issues. While it can identify the web server's name and version from HTTP headers, its fingerprinting depth is limited to basic server-level information and it does not systematically analyze client-side frameworks, JavaScript libraries, or CMS-specific markers. Therefore, Nikto may incidentally reveal some technology details during a vulnerability scan, but it is not a dedicated or comprehensive tool for website technology fingerprinting.
- ✗
Nmap
Why it's wrong here
Nmap is a network and port scanning tool that performs service/version detection using the -sV flag, which probes open ports and inspects banner messages to infer the underlying service. When applied to HTTP, this detection is typically limited to identifying the web server software (e.g., Apache, nginx) and its version, as derived from HTTP headers or server banners. Nmap does not fetch and render web pages, execute client-side JavaScript, or parse HTML content for framework signatures, making its web technology detection shallow compared to dedicated fingerprinting tools. Thus, while Nmap is excellent for host and service discovery, it is not optimized for the nuanced task of identifying the complete web technology stack.
- ✗
Gobuster
Why it's wrong here
Gobuster is a security tool designed for content discovery, using wordlist-based brute forcing to locate hidden directories, filenames, subdomains, or virtual hosts on a web server. It sends a series of HTTP requests and identifies valid paths by analyzing HTTP response codes (e.g., 200, 301, 404), but it does not inspect the content of successful responses to identify technologies. Because Gobuster focuses solely on mapping the web application's structure rather than analyzing its HTML, cookies, or headers for technology signatures, it is incapable of determining the underlying CMS, JavaScript libraries, or server-side frameworks. Its purpose is orthogonal to website fingerprinting, making it an incorrect choice for this task.
- ✓
WhatWeb
Why this is correct
WhatWeb is a dedicated website fingerprinting tool that uses a vast repository of plugins and signatures to identify the technologies powering a web application. It analyzes a wide range of signals, including HTTP headers, HTML source code, meta tags, cookies, script URLs, and inline JavaScript variables, to detect CMS platforms, web frameworks, JavaScript libraries, analytics tools, and even specific version numbers. WhatWeb assigns confidence ratings to each detection, allowing a penetration tester to accurately map the technology stack before selecting targeted attack techniques. This purpose-built nature and comprehensive signature coverage make WhatWeb the correct choice for website technology fingerprinting.
Go deeper
Related to this question
Learn chapter
Network Exploitation
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Port scanning
Port scanning is the process of probing a computer or network device to discover which network ports are open, closed, or filtered, revealing potential entry points for services and applications.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.