CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A tester needs to quickly identify outdated server software versions, dangerous default files, and insecure HTTP headers on a company's public web server before performing deeper manual testing. Which tool is best suited for this initial pass?
- ANikto
- BResponder
- CKismet
- DHydra
Show answer & explanationAnswer & explanation
Correct answer: A. Nikto
Nikto is a web server scanner specifically designed to detect outdated software, dangerous files/CGIs, and misconfigurations quickly, making it ideal for initial web app reconnaissance.
Why the other options are wrong
- B. Responder captures and poisons LLMNR/NBT-NS traffic on internal networks.
- C. Kismet is a wireless network detector, not a web scanner.
- D. Hydra is an online password brute-forcing tool.
Nikto
An open-source web server scanner that checks for outdated software, dangerous files, and common misconfigurations.
- Command-line tool, often paired with Nmap results
- Checks thousands of known vulnerable files/CGIs
- Generates a lot of noise, not stealthy
Memory trick: 'Nikto Knocks on Web Doors' first