PT0-002 Reconnaissance and Enumeration Practice Question
During a web application penetration test, the tester wants to discover hidden directories and files on the target web server. Which tool is best suited for this task, and what technique does it use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Gobuster - directory brute forcing
Directory enumeration tools like gobuster, dirbuster, and dirsearch use wordlist-based brute force to discover hidden directories and files. Gobuster is a common choice. Wappalyzer is for technology fingerprinting, whatweb is for web server identification, and curl is for HTTP requests but lacks directory brute force functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Curl - manual HTTP requests
Why it's wrong here
Curl is a command-line tool for transferring data with URLs, allowing manual HTTP requests to test specific endpoints, headers, and methods. However, it lacks built-in enumeration logic; it cannot systematically iterate through a wordlist to discover hidden directories unless you write a wrapper script around it. In the context of directory brute forcing, using curl alone would require tedious manual or scripted loops, making it inefficient and error-prone compared to dedicated tools like Gobuster.
- ✗
Whatweb - web server identification
Why it's wrong here
Whatweb is a web scanner that recognizes a wide range of web technologies, including server headers, CMS platforms, JavaScript libraries, and meta tags. It is designed for fingerprinting and reconnaissance, not for probing the filesystem structure or enumerating unlinked directories. While it can make requests to a target, it does not perform brute-force attacks against directory names or paths; it analyzes the responses of known URLs. Therefore, it would not reveal hidden directories that are not linked or referenced, as its focus is on identifying what is already served at known endpoints.
- ✗
Wappalyzer - technology fingerprinting
Why it's wrong here
Wappalyzer is a browser extension and API that detects technologies used on a website by examining content, headers, and JavaScript variables. It excels at identifying frameworks, analytics tools, and other client-side and server-side technologies. However, its methodology is passive fingerprinting of a single page or a set of provided pages; it does not conduct active enumeration of unknown paths. Wappalyzer has no concept of testing a wordlist of potential directory names, so it cannot discover hidden directories that the application does not voluntarily expose.
- ✓
Gobuster - directory brute forcing
Why this is correct
Gobuster is a tool specifically designed for brute-forcing URIs (directories and files) by systematically sending HTTP requests for each entry in a wordlist against the target web server. It is highly efficient, supporting multi-threading, status-code filtering, and extensions, making it ideal for discovering hidden or unlisted resources. Because it automates the iterative request-response cycle and parses responses for valid HTTP status codes, it is the appropriate choice for directory brute forcing in a penetration test. Unlike the other tools, it directly addresses the task of enumerating directory structure.
Go deeper
Related to this question
Learn chapter
SQL Injection: Union, Blind, Time-Based
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Fingerprinting
Fingerprinting is the process of gathering information about a target system or network to identify its operating system, services, software versions, and configuration details during the reconnaissance phase of a security assessment.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.