PT0-002 Reconnaissance and Enumeration Practice Question
During a web application penetration test, the tester wants to discover hidden parameters that the application accepts. Which THREE tools are BEST suited for parameter bruteforcing? (Select THREE.)
⚠ Common exam trap
Many exam-takers confuse general web vulnerability scanners (like Nikto or WPScan) with tools that are purpose-built for parameter bruteforcing, leading them to select tools that lack the specific functionality for discovering hidden parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Arjun
Arjun (B) is purpose-built for hidden parameter discovery, sending large wordlists of parameter names and analyzing response differences (length, status, reflection) to identify accepted parameters. ffuf (D) is a fast web fuzzer that can brute-force parameter names by fuzzing the query string or POST body with the FUZZ keyword and filtering responses by size, words, or status code. Burp Suite Intruder (E) supports parameter bruteforcing by placing payload positions on parameter names and using sniper/cluster-bomb attacks with wordlists, then reviewing response length or status changes. WPScan (A) is a WordPress vulnerability scanner focused on plugins, themes, and users, not generic parameter discovery. Nikto (C) is a web server scanner that checks for misconfigurations and known files, but it does not perform parameter-name bruteforcing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPScan
Why it's wrong here
WPScan is a WordPress security scanner that enumerates plugin, theme, and user information and checks for known vulnerabilities using version fingerprints and its vulnerability database. It does not actively brute-force or fuzz HTTP parameter names; while its vulnerability checks may reference specific vulnerable parameters, the tool's purpose is site hardening and WordPress research, not generic hidden-parameter discovery.
- ✓
Arjun
Why this is correct
Arjun is a dedicated parameter discovery tool that tries thousands of common parameter names against a target endpoint and detects hidden parameters by analyzing response differences such as reflected values, status code or content-length changes, and timing anomalies. It uses a built-in curated wordlist and supports heuristics, making it far more specialized and efficient for this task than general-purpose scanners. This purpose-built design is why it is the correct answer here.
- ✗
Nikto
Why it's wrong here
Nikto is an outdated-style web server scanner that sends a fixed set of crafted requests to identify default files, misconfigurations, outdated server software, and known vulnerable CGIs. It does not perform iterative parameter fuzzing or accept a wordlist to brute-force parameter names; its checks are pre-defined and target file/path issues, not the discovery of undisclosed request parameters on a specific endpoint.
- ✓
ffuf
Why this is correct
ffuf is a fast, multithreaded fuzzer used to discover content by replacing a FUZZ keyword in URLs, headers, cookies, or request bodies with entries from a user-supplied wordlist. For parameter discovery, you can place FUZZ in the query string or POST data and evaluate response metrics like status code, size, words, or lines to infer which parameter names are handled by the application. Its flexibility, performance, and configurable matching/filtering make it a valid tool for hidden-parameter enumeration.
- ✓
Burp Suite Intruder
Why this is correct
Burp Suite Intruder is an automated attack engine within the Burp proxy that lets you define one or more payload positions in a raw request and cycle through a wordlist of candidate parameter names while automatically measuring response length, timing, status codes, and modifiable match rules. It can be used for parameter brute-forcing by, for example, setting the parameter name position and supplying an extensive dictionary, and it provides a rich GUI for sorting and triaging results. This capability makes it a legitimate choice for parameter discovery.
Go deeper
Related to this question
Learn chapter
WPA3 and Modern Wireless Attacks
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
Key term
Nikto
Nikto is an open-source web server scanner that tests for potentially dangerous files, outdated server software, and configuration issues.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.