PEN-200 Enumeration and Reconnaissance Practice Question
You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?
⚠ Common exam trap
Candidates often suggest manual source code inspection. Automated tools are far more efficient and reliable for identifying the CMS signature across various HTTP headers and file paths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use tools like whatweb or Wappalyzer.
Automated tools like 'wappalyzer' or 'whatweb' are highly effective at identifying the underlying technology stack of a web application. They analyze HTTP headers, source code patterns, and common file paths to detect CMS platforms. Identifying the CMS is critical because it allows the tester to focus on known vulnerabilities associated with that specific platform, rather than spending time on generic web assessments that may yield fewer results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually inspect every image on the site.
Why it's wrong here
Manually inspecting images is an inefficient and ineffective way to identify a CMS. While some images might contain branding, it is not a reliable method for determining the underlying framework version or specific configuration, making it a poor choice compared to automated tools that analyze the source code.
- ✓
Use tools like whatweb or Wappalyzer.
Why this is correct
Whatweb and Wappalyzer are specialized reconnaissance tools that automatically detect the software stack, including the CMS, by analyzing server headers and page source code. This is the professional standard for quickly identifying the application framework, which is essential for tailoring your exploitation strategy to the specific target platform.
- ✗
Perform a denial-of-service attack.
Why it's wrong here
A denial-of-service attack is illegal and unethical in most penetration testing contexts. It is also completely unnecessary for service identification. Such actions are destructive and provide no information regarding the CMS, serving only to damage the target's availability and potentially alert the security team to your presence.
- ✗
Guess the CMS by looking at the page title.
Why it's wrong here
Guessing based on the page title is highly unreliable and unscientific. Titles are easily modified and provide no definitive proof of the underlying technology. Relying on guesses instead of factual evidence will lead to incorrect assumptions and waste valuable time during the reconnaissance phase of your penetration test.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.