Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are performing active reconnaissance against a web server and want to identify hidden directories and files that may not be linked from the main site. Which two techniques are most appropriate for this goal? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse port scanning or DNS enumeration with web content discovery; only techniques that interact with the web server at the HTTP layer will reveal hidden directories and files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a tool like Gobuster with a wordlist to brute-force common directory and file names.

Brute-forcing with Gobuster and inspecting robots.txt are both effective for discovering hidden directories and files on a web server. Gobuster actively probes for common names, while robots.txt may list disallowed paths that administrators wish to keep out of search engines. The other techniques focus on port scanning, DNS, or registration data, which do not directly enumerate web content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running a full TCP port scan with Nmap to identify all open ports on the server.

    Why it's wrong here

    A full TCP port scan identifies open ports and services, but it does not discover hidden web directories or files. Port scanning is useful for finding additional services, but the goal here is to find hidden content on the web server itself, which requires HTTP-level enumeration, not port scanning.

  • ✓

    Using a tool like Gobuster with a wordlist to brute-force common directory and file names.

    Why this is correct

    Gobuster is a specialized tool for brute-forcing URIs (directories and files) on web servers. It sends HTTP requests for each word in a wordlist and analyzes the response codes to identify existing resources. This is a standard active reconnaissance technique to discover hidden content that is not linked from the visible site.

  • ✓

    Inspecting the robots.txt file for disallowed entries that may reveal sensitive paths.

    Why this is correct

    The robots.txt file is intended to guide search engine crawlers, but it often lists directories that the administrator wants to hide from search engines. These entries can point to administrative panels, backup directories, or other sensitive locations. Checking robots.txt is a quick and effective passive step that can reveal hidden paths without brute-forcing.

  • ✗

    Performing a WHOIS lookup to gather registration details about the domain.

    Why it's wrong here

    WHOIS lookups provide information about domain registration, such as registrant contact details and name servers. They do not reveal hidden directories or files on the web server. This is a passive reconnaissance technique for gathering organizational information, not for web content discovery.

  • ✗

    Using the `dig` command to perform a zone transfer on the DNS server.

    Why it's wrong here

    A DNS zone transfer (AXFR) can reveal subdomains and hostnames, but it does not directly discover hidden directories or files on a web server. While it can expand the attack surface by finding other hosts, it does not enumerate content within the web root. Thus, it is not the most appropriate for the specific goal.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.