Courseiva
Vulnerability Management →easyMultiple Select

CS0-003 Vulnerability Management Practice Question

A security analyst is setting up a vulnerability management program and needs to select tools for container image scanning. Which THREE of the following are commonly used container image scanning tools? (Select THREE.)

⚠ Common exam trap

The trap is picking a well-known security tool (OpenVAS, Burp) that scans networks or web apps rather than container images — candidates who don't distinguish scanner categories will select the wrong tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Snyk

Snyk (A) is a widely used container image scanning tool that detects known vulnerabilities in OS packages and application dependencies within images, integrating into CI/CD pipelines. Clair (D) is an open-source static analysis tool from CoreOS/Quay that scans container image layers against vulnerability databases to report known CVEs. Trivy (E) is an Aqua Security open-source scanner that detects OS package and language-specific dependency vulnerabilities, misconfigurations, and secrets in container images. OpenVAS (B) is a network vulnerability scanner for hosts and services, not a container image scanner, and Burp Suite (C) is a web application security testing proxy, so neither is designed for scanning container images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Snyk

    Why this is correct

    Snyk scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines and registries. It is a widely adopted container image scanning tool, satisfying the selection criterion for this programme.

  • ✗

    OpenVAS

    Why it's wrong here

    OpenVAS scans hosts and network services for vulnerabilities; it does not inspect container image layers or package manifests. It is tempting because it is a genuine vulnerability scanner, but image scanning requires tools such as Trivy, Clair, or Anchore that parse image contents.

  • ✗

    Burp Suite

    Why it's wrong here

    Burp Suite is a web application proxy for testing live HTTP traffic, not a container image scanner. It is tempting because it detects vulnerabilities, but it operates against running web apps rather than inspecting image layers and package manifests for known CVEs.

  • ✓

    Clair

    Why this is correct

    Clair is an open-source static analyser that inspects container image layers against vulnerability databases, commonly deployed alongside registries such as Quay. It is a recognised container image scanning tool, satisfying the selection criterion for this programme.

  • ✓

    Trivy

    Why this is correct

    Trivy is an open-source scanner that inspects container images for OS package and language dependency vulnerabilities, satisfying the stem's requirement for a commonly used container image scanning tool. It integrates into CI/CD pipelines and scans both image layers and filesystems.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.