CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A tester needs to quickly identify outdated server software versions, dangerous default files, and insecure HTTP headers on a company's public web server before performing deeper manual testing. Which tool is best suited for this initial pass?

  1. ANikto
  2. BResponder
  3. CKismet
  4. DHydra
Show answer & explanation

Correct answer: A. Nikto

Nikto is a web server scanner specifically designed to detect outdated software, dangerous files/CGIs, and misconfigurations quickly, making it ideal for initial web app reconnaissance.

Why the other options are wrong

  • B. Responder captures and poisons LLMNR/NBT-NS traffic on internal networks.
  • C. Kismet is a wireless network detector, not a web scanner.
  • D. Hydra is an online password brute-forcing tool.

Nikto

An open-source web server scanner that checks for outdated software, dangerous files, and common misconfigurations.

  • Command-line tool, often paired with Nmap results
  • Checks thousands of known vulnerable files/CGIs
  • Generates a lot of noise, not stealthy

Memory trick: 'Nikto Knocks on Web Doors' first

More Vulnerability Discovery and Analysis questions