Quiz 6 Question 17 of 20

A SOC analyst receives a report that a public web app may have hidden administrative endpoints returning sensitive data. Host vulnerability scans show no known CVEs on the server. Which scanning method should be used to find undocumented or exposed API routes?

Select an answer to reveal the explanation.

Motivation