CS0-003 Vulnerability Management Practice Question
A security analyst is configuring a container image scanning tool. Which of the following tools is specifically designed for container image vulnerability scanning?
⚠ Common exam trap
CS0-004 often tests the confusion between general-purpose vulnerability scanners (Nessus, OpenVAS) and specialized container image scanners (Trivy), so candidates must recognize that container scanning requires tools that understand image layers and package manifests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trivy
Trivy is an open-source, purpose-built vulnerability scanner for container images, filesystems, and Git repositories. It scans OS packages (e.g., Alpine apk, Debian dpkg) and language-specific dependencies (npm, pip, Maven) inside an image and reports CVEs with severity ratings. Unlike general-purpose scanners, Trivy understands image layers and package manifests, making it the tool specifically designed for container image scanning in this list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nessus
Why it's wrong here
While Nessus can perform compliance checks on container hosts, it is primarily a network-based, general-purpose vulnerability scanner. It lacks the native capability to deeply parse container image layers, manifest files, and application-level dependencies within a container registry or CI/CD pipeline.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is an interception proxy and dynamic application security testing (DAST) tool designed to analyze running web applications for vulnerabilities like SQL injection and cross-site scripting. It does not scan static container images, their base operating system packages, or their embedded library dependencies.
- ✗
OpenVAS
Why it's wrong here
OpenVAS is an open-source network vulnerability scanner designed to detect security issues across active network hosts, operating systems, and services. It is not architected to unpack container image filesystems, inspect Dockerfiles, or analyze software composition (SCA) within container registries.
- ✓
Trivy
Why this is correct
Trivy is a highly specialized, open-source vulnerability and misconfiguration scanner designed specifically for containers and other cloud-native targets. It excels at scanning container images, Git repositories, and Kubernetes configurations to detect OS package vulnerabilities and application dependency flaws directly within CI/CD pipelines.
Go deeper
Related to this question
Learn chapter
Attack Simulation Tools: Atomic Red Team
Key term
Vulnerability scanner
A vulnerability scanner is an automated tool that identifies security weaknesses in systems, networks, and applications by comparing their configurations and software versions against known vulnerability databases.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.