Courseiva
Vulnerability Management →easyMultiple Select

CS0-003 Vulnerability Management Practice Question

A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?

⚠ Common exam trap

CS0-004 often tests tool categorization, so candidates confuse host auditing tools like Lynis or protocol analyzers like Wireshark with true vulnerability scanners, which enumerate CVEs against targets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nessus

Nessus (B) is a commercial vulnerability scanner from Tenable that performs credentialed and uncredentialed scans to detect missing patches, misconfigurations, and CVEs, making it a core vulnerability management tool. Qualys (D) is a cloud-based vulnerability management platform whose QualysGuard/VMDR scanners continuously assess hosts and web applications for vulnerabilities, so it clearly belongs in this category. OpenVAS (E), maintained as the Greenbone Vulnerability Management (GVM) scanner, is an open-source vulnerability scanner that uses network vulnerability tests (NVTs) to identify known flaws, qualifying it as a scanning tool. Lynis (A) is a host-based security auditing tool that checks system hardening and compliance rather than scanning for vulnerabilities across assets, and Wireshark (C) is a packet capture and protocol analysis tool used for traffic inspection, not vulnerability scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Lynis

    Why it's wrong here

    Lynis is an open-source security auditing tool that performs host-based checks against CIS benchmarks and hardening guidelines. It inspects configuration files, installed packages, and system settings to produce hardening suggestions, but it does not scan for known CVEs or enumerate network services for vulnerabilities. Therefore, while useful for compliance posture assessments, it is not a vulnerability scanner in the context of selecting a vulnerability management tool.

  • ✓

    Nessus

    Why this is correct

    Nessus is a commercial vulnerability scanner developed by Tenable that actively scans hosts and network services, comparing software versions and configurations against a comprehensive plugin database of known Common Vulnerabilities and Exposures (CVEs). It supports credentialed scans, agent-based scanning, and integration with patch management and SIEM platforms, making it a primary tool for continuous vulnerability management. This directly matches the goal of identifying exploitable weaknesses across an enterprise.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures and inspects individual packets in real time, decoding protocols like TCP/IP, HTTP, and TLS to troubleshoot network issues or perform traffic analysis. It does not maintain a vulnerability signature database, nor does it probe systems to identify missing patches, misconfigurations, or exposure to known exploits. Thus it is a packet-level forensics/troubleshooting tool, not a vulnerability scanner for management workflows.

  • ✓

    Qualys

    Why this is correct

    Qualys provides a cloud-based vulnerability management platform where scanners, agents, and APIs continuously inventory assets and detect vulnerabilities by querying a distributed set of scan engines over the internet without an on-premises scanner. It correlates findings with threat intelligence and offers dashboards, prioritization, and automated remediation workflows via its Cloud Platform. This makes it a scalable, SaaS-based fit for selecting a vulnerability management tool.

  • ✓

    OpenVAS

    Why this is correct

    OpenVAS (Open Vulnerability Assessment Scanner) is an open-source scanner that evolves from the Nessus after Tenable went commercial, and it runs scheduled scans using a large feed of Network Vulnerability Tests (NVTs). It performs authenticated and unauthenticated checks against hosts, including plugin-based detection of OS and application CVEs, and outputs reports with severities and recommendations. As a freely available scanner with active community support, it is a legitimate choice for vulnerability assessment, especially for budget-constrained environments.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.