PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting a vulnerability scan on a web server using Nikto. The scan report lists several findings, including a directory listing vulnerability and outdated server headers. Which type of scanner is Nikto?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server vulnerability scanner
Nikto is a web server scanner that tests for misconfigurations, outdated software, and common vulnerabilities. Nessus is a general vulnerability scanner, WPScan is for WordPress, and OpenVAS is also a general vulnerability scanner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network port scanner
Why it's wrong here
A network port scanner such as Nmap enumerates open TCP/UDP ports and identifies running services across hosts, focusing on network-layer reachability. It does not perform HTTP-specific tests against web server software, such as checking for dangerous CGI scripts, default files, or server header misconfigurations. Nikto, by contrast, operates at the application layer and is designed specifically to probe web server vulnerabilities, so it is not accurately classified as a network port scanner.
- ✗
WordPress vulnerability scanner
Why it's wrong here
WPScan is a dedicated WordPress vulnerability scanner that exclusively targets WordPress core, plugin, and theme vulnerabilities using a WordPress-specific signature database. Nikto is a broader-purpose web server vulnerability scanner that checks for a generic range of insecure files, outdated server software, and configuration issues across any web platform, including Apache, Nginx, and IIS, without requiring a CMS identification step. Therefore, while Nikto may incidentally detect WordPress-related issues, its scope is far wider than a WordPress scanner.
- ✓
Web server vulnerability scanner
Why this is correct
Nikto is a purpose-built web server vulnerability scanner that performs automated HTTP/HTTPS checks for over 7,000 potentially dangerous files and programs, outdated server software, and server misconfigurations, such as insecure HTTP methods and default credentials. It inspects response headers and content to fingerprint the exact server version and cross-references it against known vulnerabilities, covering platforms like Apache, Nginx, and IIS. This makes 'web server vulnerability scanner' the precise and correct classification for Nikto's role in a penetration test.
- ✗
General vulnerability scanner
Why it's wrong here
A general vulnerability scanner such as Nessus or OpenVAS conducts comprehensive network-wide assessments, enumerating host operating systems, open ports, and installed software, and then cross-checks them against massive vulnerability databases using both authenticated and unauthenticated checks. These tools are broad and cover a wide range of OS-level and application-level weaknesses across many hosts. Nikto, in contrast, is narrowly scoped to a single web server target and focuses exclusively on HTTP-level issues, so it is not a general vulnerability scanner.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Nikto
Nikto is an open-source web server scanner that tests for potentially dangerous files, outdated server software, and configuration issues.
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.