Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

⚠ Common exam trap

Candidates often focus only on finding a single vulnerability on the homepage, neglecting input fields, parameters, and hidden administrative directories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hidden directories and files.

Effective web enumeration requires looking beyond the main page. Identifying hidden directories, software versions, and input fields allows a tester to map the attack surface comprehensively. By finding these components, a tester can research known vulnerabilities associated with specific technologies or test for common web flaws like SQL injection or cross-site scripting, which are frequently found in custom application code and forgotten administrative paths.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hidden directories and files.

    Why this is correct

    Hidden directories often contain configuration files, backup scripts, or administrative interfaces that lack proper authentication. Identifying these paths provides a significant advantage, as they may contain sensitive information or serve as entry points that bypass the main application's security controls, providing easier access for a penetration tester.

  • ✓

    The web server software and version.

    Why this is correct

    Knowing the web server's software and version is critical for identifying specific, known vulnerabilities. Many older or unpatched versions have public exploits available, allowing a tester to quickly research and apply targeted tests, which is often more efficient than attempting to find flaws in the custom application layer.

  • ✓

    User input fields and URL parameters.

    Why this is correct

    Input fields and URL parameters are the primary vectors for common web vulnerabilities like SQL injection, XSS, and command injection. Identifying where the application processes user-supplied data allows a tester to craft malicious payloads to test the application's sanitization and security logic against common attack patterns.

  • ✗

    The color scheme of the website.

    Why it's wrong here

    The visual design and color scheme of a website do not provide any information regarding security posture or potential vulnerabilities. Focusing on superficial elements wastes time and distracts from the technical reconnaissance required to identify exploitable code or configuration weaknesses in the underlying application and server infrastructure.

  • ✗

    The number of images hosted on the server.

    Why it's wrong here

    The quantity of images hosted has no relevance to the security of the application. While image metadata might occasionally reveal minor information, the count itself is a distraction that does not aid in finding logical flaws, misconfigurations, or software vulnerabilities necessary for successful exploitation during a penetration test.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.