PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester has discovered a web application that appears to be built with WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities without triggering intrusion detection systems. Which tool is BEST suited for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPScan
WPScan is a dedicated WordPress vulnerability scanner that can enumerate plugins, themes, users, and known vulnerabilities. It can be configured to use passive methods or throttle requests to avoid detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OpenVAS
Why it's wrong here
OpenVAS is a broad-scope vulnerability scanner that performs credentialed and uncredentialed checks across many protocols (e.g., SNMP, SSH, SMB) and generic web issues. It does not include WordPress-specific logic for fingerprinting core versions, enumerating plugins/themes, or mapping them to WordPress-focused vulnerability feeds. For a dedicated WordPress web app test, OpenVAS would produce noisy, general findings and miss the targeted plugin/theme CVEs that WPScan identifies.
- ✗
Nikto
Why it's wrong here
Nikto is an open-source web server scanner that focuses on detecting outdated server software, dangerous files, and common misconfigurations through a large check database. While it can probe web applications, it lacks a WordPress-oriented plugin/theme vulnerability database and does not perform user enumeration or login brute-force testing tailored to WordPress. Thus, it may flag generic web issues but cannot reliably assess the specific security posture of a WordPress instance.
- ✓
WPScan
Why this is correct
WPScan is the correct choice because it is a purpose-built WordPress security scanner. It enumerates WordPress core, plugin, and theme versions, checks them against known CVE databases, and can identify usernames, weak passwords, and vulnerable components. Its specialized fingerprinting engine and integration with the WPScan API give it far higher accuracy for WordPress-specific vulnerabilities than any general-purpose scanner.
- ✗
Gobuster
Why it's wrong here
Gobuster is a fast tool for brute-forcing directories, files, and DNS subdomains using wordlists; it is not a vulnerability scanner at all. It simply discovers resource paths or virtual host entries and returns HTTP status codes, without inspecting software versions or correlating them with known vulnerabilities. For this scenario, Gobuster would only help map an attack surface, not identify whether the WordPress application has exploitable flaws.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.