Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

While performing web application reconnaissance, a tester wants to enumerate hidden directories and files on a web server. Which of the following tools is specifically designed for directory brute-forcing?

⚠ Common exam trap

A common mix-up: candidates confuse Nikto's web scanning capabilities with directory brute-forcing, but Nikto's focus is on vulnerability detection rather than enumerating hidden paths via wordlists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Gobuster

Gobuster is specifically designed for directory brute-forcing by using a wordlist to discover hidden directories and files on a web server. It sends HTTP GET requests to the target and reports valid responses (e.g., 200, 301, 403), making it the correct tool for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web server scanner that catalogs known vulnerabilities, misconfigurations, and outdated software by sending crafted HTTP requests. Although it has a small built-in list of default file and directory checks, this is incidental to its core function of vulnerability identification, not a comprehensive wordlist-driven brute-force mechanism. For a tester seeking to systematically uncover hidden directories across an arbitrary web app, Nikto's static checks are too shallow and lack the flexibility of a dedicated fuzzer like Gobuster.

  • ✓

    Gobuster

    Why this is correct

    Gobuster is a specialized tool for brute-forcing directories, files, and DNS subdomains using user-supplied wordlists. It generates HTTP requests and evaluates response codes to identify valid paths, making it highly efficient for web application reconnaissance. The tool supports multiple modes (dir, dns, vhost), custom extensions, and threading options, giving testers precise control over enumeration depth and speed. This dedicated focus on resource discovery is exactly what the scenario requires.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is a purpose-built scanner for WordPress instances, enumerating plugins, themes, users, and known WordPress vulnerabilities. It does not perform general-purpose directory brute-forcing on arbitrary web applications, as its checks are tightly coupled to WordPress-specific structures and APIs. Unless the reconnaissance explicitly identifies a WordPress installation (which the question does not), WPScan is not a suitable substitute for a generic directory fuzzer like Gobuster.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network and port scanner that discovers hosts, services, and open ports; its NSE scripts include http-enum, which can probe for a handful of common web paths. However, that script is not designed for exhaustive wordlist-driven brute-forcing, and invoking it through Nmap is clunky and slower than a dedicated fuzzer. With its primary focus on network-level enumeration, Nmap lacks the repetition, concurrency, and refined HTTP status interpretation needed for thorough web path discovery.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.