A SOC analyst receives a report that a public web app may have hidden administrative endpoints returning sensitive data. Host vulnerability scans show no known CVEs on the server. Which scanning method should be used to find undocumented or exposed API routes?
Select an answer to reveal the explanation.
Short Explanation
It's a side-door hunt: a host scan only checks doors you already know about. If the worry is hidden API routes, you'll use API endpoint discovery. The trap is assuming no CVEs means no exposure.
Full Explanation
API endpoint discovery scanning maps application surfaces by probing expected, enumerated, and fuzzed paths to reveal undocumented or exposed API routes. It is chosen when the risk is hidden attack surface, such as admin endpoints or forgotten versioned APIs, even when host scans report no known CVEs. An authenticated host vulnerability scan is not ideal because it validates known software flaws on systems and applications using credentials, not primarily discovering unknown routes. An unauthenticated external port scan is too narrow; it identifies open network services but does not reliably enumerate application endpoints or route behavior. A configuration compliance scan evaluates settings against benchmarks or policy baselines, which can flag insecure configurations but does not discover hidden API paths. Exam caveat: choose API discovery when the scenario emphasizes unknown, exposed, or undocumented application endpoints rather than known vulnerabilities or baseline drift. Operational check: run a credentialed API discovery scan against a staging application, compare discovered routes with the documented API specification, and triage any undocumented endpoints.