PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is evaluating the security of a WordPress site. Which tool is specifically designed to scan WordPress installations for vulnerabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPScan
WPScan is a dedicated WordPress vulnerability scanner that checks for known vulnerabilities in WordPress core, plugins, and themes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nessus
Why it's wrong here
Nessus is a commercial, general-purpose vulnerability scanner from Tenable that covers a wide range of network, OS, database, and application CVEs. Although it ships with some web application plugins and can identify certain WordPress issues, its WordPress checks are generic and not powered by a dedicated WordPress vulnerability database. For a thorough WordPress-specific security evaluation, a tester needs the CMS-aware enumeration that WPScan provides. Therefore, Nessus, while useful for broader infrastructure scanning, is not the correct dedicated tool for this purpose.
- ✓
WPScan
Why this is correct
WPScan is an open-source security scanner purpose-built for WordPress, included by default in distributions like Kali Linux. It enumerates the WordPress core version, installed themes and plugins, user accounts, and backup or configuration files, then cross-references findings against the WPScan API vulnerability database. This allows it to identify known vulnerabilities in plugins and themes that generic scanners often miss. Because the question asks for a tool specifically for evaluating WordPress security, WPScan is the correct answer.
- ✗
OpenVAS
Why it's wrong here
OpenVAS is an open-source vulnerability scanner maintained by Greenbone that relies on a large feed of Network Vulnerability Tests (NVTs) to identify missing patches and configuration flaws across hosts and services. It is a broad infrastructure scanner, not a CMS-focused tool, and while it may include occasional web checks, it lacks the WordPress-specific enumeration capabilities and dedicated advisory database that WPScan offers. OpenVAS would not deeply analyze a WordPress installation's plugins, themes, or user structure, making it incorrect for a focused WordPress assessment.
- ✗
Nikto
Why it's wrong here
Nikto is an open-source web server scanner designed to check for dangerous files, misconfigured server modules, outdated server software, and known web server vulnerabilities. Although it can inspect for certain WordPress plugins and common files, its perspective is the web server and HTTP layer rather than the WordPress application itself. Nikto does not enumerate WordPress users, themes, plugins in depth, or consult a WordPress-specific vulnerability database, so it lacks the precision needed for a dedicated WordPress security evaluation.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.