Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester has discovered a web application that appears to be built with WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities without triggering intrusion detection systems. Which tool is BEST suited for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPScan

WPScan is a dedicated WordPress vulnerability scanner that can enumerate plugins, themes, users, and known vulnerabilities. It can be configured to use passive methods or throttle requests to avoid detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OpenVAS

    Why it's wrong here

    OpenVAS is a broad-scope vulnerability scanner that performs credentialed and uncredentialed checks across many protocols (e.g., SNMP, SSH, SMB) and generic web issues. It does not include WordPress-specific logic for fingerprinting core versions, enumerating plugins/themes, or mapping them to WordPress-focused vulnerability feeds. For a dedicated WordPress web app test, OpenVAS would produce noisy, general findings and miss the targeted plugin/theme CVEs that WPScan identifies.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is an open-source web server scanner that focuses on detecting outdated server software, dangerous files, and common misconfigurations through a large check database. While it can probe web applications, it lacks a WordPress-oriented plugin/theme vulnerability database and does not perform user enumeration or login brute-force testing tailored to WordPress. Thus, it may flag generic web issues but cannot reliably assess the specific security posture of a WordPress instance.

  • ✓

    WPScan

    Why this is correct

    WPScan is the correct choice because it is a purpose-built WordPress security scanner. It enumerates WordPress core, plugin, and theme versions, checks them against known CVE databases, and can identify usernames, weak passwords, and vulnerable components. Its specialized fingerprinting engine and integration with the WPScan API give it far higher accuracy for WordPress-specific vulnerabilities than any general-purpose scanner.

  • ✗

    Gobuster

    Why it's wrong here

    Gobuster is a fast tool for brute-forcing directories, files, and DNS subdomains using wordlists; it is not a vulnerability scanner at all. It simply discovers resource paths or virtual host entries and returns HTTP status codes, without inspecting software versions or correlating them with known vulnerabilities. For this scenario, Gobuster would only help map an attack surface, not identify whether the WordPress application has exploitable flaws.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.