CS0-003 Vulnerability Management Practice Question
A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?
⚠ Common exam trap
CS0-004 often tests tool categorization, so candidates confuse host auditing tools like Lynis or protocol analyzers like Wireshark with true vulnerability scanners, which enumerate CVEs against targets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Nessus
Nessus (B) is a commercial vulnerability scanner from Tenable that performs credentialed and uncredentialed scans to detect missing patches, misconfigurations, and CVEs, making it a core vulnerability management tool. Qualys (D) is a cloud-based vulnerability management platform whose QualysGuard/VMDR scanners continuously assess hosts and web applications for vulnerabilities, so it clearly belongs in this category. OpenVAS (E), maintained as the Greenbone Vulnerability Management (GVM) scanner, is an open-source vulnerability scanner that uses network vulnerability tests (NVTs) to identify known flaws, qualifying it as a scanning tool. Lynis (A) is a host-based security auditing tool that checks system hardening and compliance rather than scanning for vulnerabilities across assets, and Wireshark (C) is a packet capture and protocol analysis tool used for traffic inspection, not vulnerability scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lynis
Why it's wrong here
Lynis is an open-source security auditing tool that performs host-based checks against CIS benchmarks and hardening guidelines. It inspects configuration files, installed packages, and system settings to produce hardening suggestions, but it does not scan for known CVEs or enumerate network services for vulnerabilities. Therefore, while useful for compliance posture assessments, it is not a vulnerability scanner in the context of selecting a vulnerability management tool.
- ✓
Nessus
Why this is correct
Nessus is a commercial vulnerability scanner developed by Tenable that actively scans hosts and network services, comparing software versions and configurations against a comprehensive plugin database of known Common Vulnerabilities and Exposures (CVEs). It supports credentialed scans, agent-based scanning, and integration with patch management and SIEM platforms, making it a primary tool for continuous vulnerability management. This directly matches the goal of identifying exploitable weaknesses across an enterprise.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and inspects individual packets in real time, decoding protocols like TCP/IP, HTTP, and TLS to troubleshoot network issues or perform traffic analysis. It does not maintain a vulnerability signature database, nor does it probe systems to identify missing patches, misconfigurations, or exposure to known exploits. Thus it is a packet-level forensics/troubleshooting tool, not a vulnerability scanner for management workflows.
- ✓
Qualys
Why this is correct
Qualys provides a cloud-based vulnerability management platform where scanners, agents, and APIs continuously inventory assets and detect vulnerabilities by querying a distributed set of scan engines over the internet without an on-premises scanner. It correlates findings with threat intelligence and offers dashboards, prioritization, and automated remediation workflows via its Cloud Platform. This makes it a scalable, SaaS-based fit for selecting a vulnerability management tool.
- ✓
OpenVAS
Why this is correct
OpenVAS (Open Vulnerability Assessment Scanner) is an open-source scanner that evolves from the Nessus after Tenable went commercial, and it runs scheduled scans using a large feed of Network Vulnerability Tests (NVTs). It performs authenticated and unauthenticated checks against hosts, including plugin-based detection of OS and application CVEs, and outputs reports with severities and recommendations. As a freely available scanner with active community support, it is a legitimate choice for vulnerability assessment, especially for budget-constrained environments.
Go deeper
Related to this question
Learn chapter
Security Metrics and KPIs
Key term
Packet capture
Packet capture is the process of intercepting and recording data packets traveling over a computer network for analysis.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.