Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is configuring a container image scanning tool. Which of the following tools is specifically designed for container image vulnerability scanning?

⚠ Common exam trap

CS0-004 often tests the confusion between general-purpose vulnerability scanners (Nessus, OpenVAS) and specialized container image scanners (Trivy), so candidates must recognize that container scanning requires tools that understand image layers and package manifests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trivy

Trivy is an open-source, purpose-built vulnerability scanner for container images, filesystems, and Git repositories. It scans OS packages (e.g., Alpine apk, Debian dpkg) and language-specific dependencies (npm, pip, Maven) inside an image and reports CVEs with severity ratings. Unlike general-purpose scanners, Trivy understands image layers and package manifests, making it the tool specifically designed for container image scanning in this list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nessus

    Why it's wrong here

    While Nessus can perform compliance checks on container hosts, it is primarily a network-based, general-purpose vulnerability scanner. It lacks the native capability to deeply parse container image layers, manifest files, and application-level dependencies within a container registry or CI/CD pipeline.

  • ✗

    Burp Suite

    Why it's wrong here

    Burp Suite is an interception proxy and dynamic application security testing (DAST) tool designed to analyze running web applications for vulnerabilities like SQL injection and cross-site scripting. It does not scan static container images, their base operating system packages, or their embedded library dependencies.

  • ✗

    OpenVAS

    Why it's wrong here

    OpenVAS is an open-source network vulnerability scanner designed to detect security issues across active network hosts, operating systems, and services. It is not architected to unpack container image filesystems, inspect Dockerfiles, or analyze software composition (SCA) within container registries.

  • ✓

    Trivy

    Why this is correct

    Trivy is a highly specialized, open-source vulnerability and misconfiguration scanner designed specifically for containers and other cloud-native targets. It excels at scanning container images, Git repositories, and Kubernetes configurations to detect OS package vulnerabilities and application dependency flaws directly within CI/CD pipelines.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.