Courseiva
Vulnerability ManagementeasyMultiple SelectObjective-mapped

CS0-003 Vulnerability Management Practice Question

A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Nessus

Nessus, Qualys, and OpenVAS are well-known vulnerability scanners. Lynis is a security auditing tool for hardening, but not primarily a vulnerability scanner, and Wireshark is a network protocol analyzer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lynis

    Why it's wrong here

    Lynis is an open-source security auditing tool that performs host-based checks against CIS benchmarks and hardening guidelines. It inspects configuration files, installed packages, and system settings to produce hardening suggestions, but it does not scan for known CVEs or enumerate network services for vulnerabilities. Therefore, while useful for compliance posture assessments, it is not a vulnerability scanner in the context of selecting a vulnerability management tool.

  • Nessus

    Why this is correct

    Nessus is a commercial vulnerability scanner developed by Tenable that actively scans hosts and network services, comparing software versions and configurations against a comprehensive plugin database of known Common Vulnerabilities and Exposures (CVEs). It supports credentialed scans, agent-based scanning, and integration with patch management and SIEM platforms, making it a primary tool for continuous vulnerability management. This directly matches the goal of identifying exploitable weaknesses across an enterprise.

  • Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures and inspects individual packets in real time, decoding protocols like TCP/IP, HTTP, and TLS to troubleshoot network issues or perform traffic analysis. It does not maintain a vulnerability signature database, nor does it probe systems to identify missing patches, misconfigurations, or exposure to known exploits. Thus it is a packet-level forensics/troubleshooting tool, not a vulnerability scanner for management workflows.

  • Qualys

    Why this is correct

    Qualys provides a cloud-based vulnerability management platform where scanners, agents, and APIs continuously inventory assets and detect vulnerabilities by querying a distributed set of scan engines over the internet without an on-premises scanner. It correlates findings with threat intelligence and offers dashboards, prioritization, and automated remediation workflows via its Cloud Platform. This makes it a scalable, SaaS-based fit for selecting a vulnerability management tool.

  • OpenVAS

    Why this is correct

    OpenVAS (Open Vulnerability Assessment Scanner) is an open-source scanner that evolves from the Nessus after Tenable went commercial, and it runs scheduled scans using a large feed of Network Vulnerability Tests (NVTs). It performs authenticated and unauthenticated checks against hosts, including plugin-based detection of OS and application CVEs, and outputs reports with severities and recommendations. As a freely available scanner with active community support, it is a legitimate choice for vulnerability assessment, especially for budget-constrained environments.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.