CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan report and notices that a plugin output indicates a potential misconfiguration in a web server that allows directory listing. The analyst wants to verify this finding manually. Which of the following tools would be most appropriate to confirm the vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Burp Suite
Burp Suite is a web application security testing tool that can be used to manually verify web vulnerabilities like directory listing by intercepting and modifying requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Burp Suite
Why this is correct
Burp Suite is an intercepting proxy designed specifically for web application security testing. It allows an analyst to intercept, modify, and replay HTTP/HTTPS requests to manually inspect the web server's responses. This makes it the ideal tool to safely and directly verify if directory listing is enabled on a specific web directory.
- ✗
Metasploit
Why it's wrong here
Metasploit is a penetration testing and exploitation framework primarily used to deliver payloads and validate vulnerabilities by executing exploits. While it contains auxiliary scanners, using it to verify a simple web misconfiguration like directory listing is inefficient and introduces unnecessary operational risk compared to a standard web proxy.
- ✗
Wireshark
Why it's wrong here
Wireshark is a deep packet inspection and packet analysis tool that captures network traffic at the frame level. While it can display HTTP traffic if unencrypted, it is not designed to actively craft requests or interactively test web application directories, making it highly inefficient for verifying this specific misconfiguration.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanning and host discovery tool used to identify open ports, running services, and operating systems. Although the Nmap Scripting Engine (NSE) has some basic HTTP scripts, Nmap lacks the granular, interactive HTTP request manipulation capabilities required to thoroughly inspect and verify complex web application-level directory listings.
Go deeper
Related to this question
Learn chapter
SAST vs DAST Tools and Integration
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.