Courseiva
Vulnerability Management →hardMultiple Select

CS0-003 Vulnerability Management Practice Question

A security team is implementing container security scanning in their CI/CD pipeline. They want to scan container images for vulnerabilities and Kubernetes misconfigurations. Which THREE tools from the following list are best suited for this purpose? (Select THREE)

⚠ Common exam trap

The trap is selecting general-purpose security tools like Burp Suite or OpenSCAP because they are well-known, but the question specifically requires container image and Kubernetes misconfiguration scanning, which only Trivy, Clair, and Snyk address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trivy

Trivy (B) is a purpose-built container and Kubernetes scanner that detects OS package and language dependency CVEs in images and also checks Kubernetes manifests and cluster configurations for misconfigurations, making it a direct fit for both requirements. Clair (D) is an open-source static analyzer from CoreOS/Quay that inspects container image layers against vulnerability databases, so it is well suited for image vulnerability scanning in a CI/CD pipeline. Snyk (E) provides container image vulnerability scanning plus Kubernetes and IaC misconfiguration detection, and it integrates natively into CI/CD workflows, satisfying both stated goals. Burp Suite (A) is a web application security testing proxy for runtime HTTP traffic, not a container image or Kubernetes configuration scanner, so it does not belong. OpenSCAP (C) is a compliance and vulnerability scanner based on SCAP for hosts and operating systems, not for container image layers or Kubernetes misconfigurations, so it is not the best fit here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Burp Suite

    Why it's wrong here

    Burp Suite is a web application security testing proxy that intercepts HTTP/S traffic to map attack surfaces and manually or automatically test for vulnerabilities such as SQL injection, XSS, and authentication bypass. It does not parse container image layers, inspect OS package inventories, or query CVE databases, and it lacks integration with container registries and CI/CD pipelines for image-level assurance. Therefore, it is fundamentally misapplied to a container security scanning initiative.

  • ✓

    Trivy

    Why this is correct

    Trivy is an open-source, fast, and comprehensive vulnerability scanner designed specifically for container images. It scans both OS packages (e.g., Alpine, Debian) and application dependencies (e.g., Python, Node.js) by comparing against a continuously updated CVE database, and it can be easily embedded into CI/CD pipelines with a simple CLI without requiring a separate server. Its low false-positive rate and support for multiple input formats (e.g., Docker, Podman, OCI) make it the most straightforward and effective choice among these options for the security team's container scanning need.

  • ✗

    OpenSCAP

    Why it's wrong here

    OpenSCAP is a security compliance framework that evaluates hosts against SCAP-backed policy baselines such as CIS benchmarks, checking system configuration, installed packages, and file permissions. While it can detect some vulnerable packages on a running host, it does not decompose container image layers, inspect image manifests, or interact with container registries, and it cannot provide vulnerability intelligence specific to the container runtime or image build process. Consequently, it is not a container-native scanning tool and is inappropriate for this task.

  • ✓

    Clair

    Why this is correct

    Clair is an open-source project originally from CoreOS that performs static analysis of security vulnerabilities in container images. It ingests images from registries, breaks them into layers, and correlates installed OS packages with CVE data via a PostgreSQL-backed API, enabling tools like Quay or custom queries to retrieve results. As a registry-integrated scanner, it is a valid option for continuous vulnerability assessment, though it requires more operational overhead—namely a database and backend services—compared to more modern single-binary scanners.

  • ✓

    Snyk

    Why this is correct

    Snyk is a developer-first security platform that offers container scanning for known vulnerabilities, license compliance, and configuration drift, with robust integrations into IDE plugins, Git repositories, and CI/CD systems. Unlike purely image-layer scanners, Snyk also performs deep dependency analysis and provides actionable fix advice, patching recommendations, and continuous monitoring through both free and commercial tiers. It is a correct tool for container security scanning, particularly when the team wants developer-friendly policy enforcement in addition to CVE detection.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.