CS0-003 Vulnerability Management Practice Question
A security analyst is setting up a vulnerability management program and needs to select tools for container image scanning. Which THREE of the following are commonly used container image scanning tools? (Select THREE.)
⚠ Common exam trap
The trap is picking a well-known security tool (OpenVAS, Burp) that scans networks or web apps rather than container images — candidates who don't distinguish scanner categories will select the wrong tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Snyk
Snyk (A) is a widely used container image scanning tool that detects known vulnerabilities in OS packages and application dependencies within images, integrating into CI/CD pipelines. Clair (D) is an open-source static analysis tool from CoreOS/Quay that scans container image layers against vulnerability databases to report known CVEs. Trivy (E) is an Aqua Security open-source scanner that detects OS package and language-specific dependency vulnerabilities, misconfigurations, and secrets in container images. OpenVAS (B) is a network vulnerability scanner for hosts and services, not a container image scanner, and Burp Suite (C) is a web application security testing proxy, so neither is designed for scanning container images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Snyk
Why this is correct
Snyk scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines and registries. It is a widely adopted container image scanning tool, satisfying the selection criterion for this programme.
- ✗
OpenVAS
Why it's wrong here
OpenVAS scans hosts and network services for vulnerabilities; it does not inspect container image layers or package manifests. It is tempting because it is a genuine vulnerability scanner, but image scanning requires tools such as Trivy, Clair, or Anchore that parse image contents.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is a web application proxy for testing live HTTP traffic, not a container image scanner. It is tempting because it detects vulnerabilities, but it operates against running web apps rather than inspecting image layers and package manifests for known CVEs.
- ✓
Clair
Why this is correct
Clair is an open-source static analyser that inspects container image layers against vulnerability databases, commonly deployed alongside registries such as Quay. It is a recognised container image scanning tool, satisfying the selection criterion for this programme.
- ✓
Trivy
Why this is correct
Trivy is an open-source scanner that inspects container images for OS package and language dependency vulnerabilities, satisfying the stem's requirement for a commonly used container image scanning tool. It integrates into CI/CD pipelines and scans both image layers and filesystems.
Go deeper
Related to this question
Learn chapter
Security Posture Reporting and Dashboards
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
Key term
OpenVAS
OpenVAS is an open-source vulnerability scanner that helps IT professionals identify security weaknesses in networks, systems, and applications.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.