Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

Which of the following tools would best assist a penetration tester in identifying known vulnerabilities in a WordPress installation?

⚠ Common exam trap

Many exam-takers choose a general-purpose vulnerability scanner like Nessus or OpenVAS because they are familiar with them, but the question specifically asks for the best tool to identify known vulnerabilities in a WordPress installation, which requires a specialized scanner like WPScan.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPScan

WPScan is specifically designed to enumerate and identify vulnerabilities in WordPress installations, including outdated plugins, themes, and core files. It uses a comprehensive database of WordPress CVEs and security issues, making it the most targeted tool for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OpenVAS

    Why it's wrong here

    OpenVAS performs authenticated and unauthenticated network vulnerability scanning against hosts and services, but it lacks WordPress-aware checks for plugin, theme and core version vulnerabilities. It is tempting as a general vulnerability scanner, yet identifying known WordPress flaws requires a CMS-specific tool that fingerprints components and matches them to advisories.

  • ✓

    WPScan

    Why this is correct

    WPScan queries the WordPress vulnerability database and enumerates core version, plugins and themes, matching each against known CVEs. That directly satisfies the stem's requirement to identify known vulnerabilities in a WordPress installation, unlike generic scanners that lack WordPress-specific signature data.

  • ✗

    Nessus

    Why it's wrong here

    Nessus is a broad infrastructure vulnerability scanner; its plugins detect host and service flaws but do not fingerprint WordPress plugins, themes and core versions against CMS-specific advisories. It is tempting because it is a well-known vulnerability scanner, yet WordPress component-level known-vulnerability identification needs a dedicated tool such as WPScan.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web server scanner that flags server misconfigurations and outdated software signatures, but it does not enumerate WordPress core, plugin or theme versions against a vulnerability database. It is tempting because it targets web servers, yet WordPress-specific known-vulnerability identification requires a dedicated scanner such as WPScan.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.