Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a web application penetration test, the tester wants to discover hidden parameters that the application accepts. Which THREE tools are BEST suited for parameter bruteforcing? (Select THREE.)

⚠ Common exam trap

Many exam-takers confuse general web vulnerability scanners (like Nikto or WPScan) with tools that are purpose-built for parameter bruteforcing, leading them to select tools that lack the specific functionality for discovering hidden parameters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Arjun

Arjun (B) is purpose-built for hidden parameter discovery, sending large wordlists of parameter names and analyzing response differences (length, status, reflection) to identify accepted parameters. ffuf (D) is a fast web fuzzer that can brute-force parameter names by fuzzing the query string or POST body with the FUZZ keyword and filtering responses by size, words, or status code. Burp Suite Intruder (E) supports parameter bruteforcing by placing payload positions on parameter names and using sniper/cluster-bomb attacks with wordlists, then reviewing response length or status changes. WPScan (A) is a WordPress vulnerability scanner focused on plugins, themes, and users, not generic parameter discovery. Nikto (C) is a web server scanner that checks for misconfigurations and known files, but it does not perform parameter-name bruteforcing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is a WordPress security scanner that enumerates plugin, theme, and user information and checks for known vulnerabilities using version fingerprints and its vulnerability database. It does not actively brute-force or fuzz HTTP parameter names; while its vulnerability checks may reference specific vulnerable parameters, the tool's purpose is site hardening and WordPress research, not generic hidden-parameter discovery.

  • ✓

    Arjun

    Why this is correct

    Arjun is a dedicated parameter discovery tool that tries thousands of common parameter names against a target endpoint and detects hidden parameters by analyzing response differences such as reflected values, status code or content-length changes, and timing anomalies. It uses a built-in curated wordlist and supports heuristics, making it far more specialized and efficient for this task than general-purpose scanners. This purpose-built design is why it is the correct answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is an outdated-style web server scanner that sends a fixed set of crafted requests to identify default files, misconfigurations, outdated server software, and known vulnerable CGIs. It does not perform iterative parameter fuzzing or accept a wordlist to brute-force parameter names; its checks are pre-defined and target file/path issues, not the discovery of undisclosed request parameters on a specific endpoint.

  • ✓

    ffuf

    Why this is correct

    ffuf is a fast, multithreaded fuzzer used to discover content by replacing a FUZZ keyword in URLs, headers, cookies, or request bodies with entries from a user-supplied wordlist. For parameter discovery, you can place FUZZ in the query string or POST data and evaluate response metrics like status code, size, words, or lines to infer which parameter names are handled by the application. Its flexibility, performance, and configurable matching/filtering make it a valid tool for hidden-parameter enumeration.

  • ✓

    Burp Suite Intruder

    Why this is correct

    Burp Suite Intruder is an automated attack engine within the Burp proxy that lets you define one or more payload positions in a raw request and cycle through a wordlist of candidate parameter names while automatically measuring response length, timing, status codes, and modifiable match rules. It can be used for parameter brute-forcing by, for example, setting the parameter name position and supplying an extensive dictionary, and it provides a rich GUI for sorting and triaging results. This capability makes it a legitimate choice for parameter discovery.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.