PT0-002 Reconnaissance and Enumeration Practice Question
Which of the following tools would best assist a penetration tester in identifying known vulnerabilities in a WordPress installation?
⚠ Common exam trap
Many exam-takers choose a general-purpose vulnerability scanner like Nessus or OpenVAS because they are familiar with them, but the question specifically asks for the best tool to identify known vulnerabilities in a WordPress installation, which requires a specialized scanner like WPScan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPScan
WPScan is specifically designed to enumerate and identify vulnerabilities in WordPress installations, including outdated plugins, themes, and core files. It uses a comprehensive database of WordPress CVEs and security issues, making it the most targeted tool for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OpenVAS
Why it's wrong here
OpenVAS performs authenticated and unauthenticated network vulnerability scanning against hosts and services, but it lacks WordPress-aware checks for plugin, theme and core version vulnerabilities. It is tempting as a general vulnerability scanner, yet identifying known WordPress flaws requires a CMS-specific tool that fingerprints components and matches them to advisories.
- ✓
WPScan
Why this is correct
WPScan queries the WordPress vulnerability database and enumerates core version, plugins and themes, matching each against known CVEs. That directly satisfies the stem's requirement to identify known vulnerabilities in a WordPress installation, unlike generic scanners that lack WordPress-specific signature data.
- ✗
Nessus
Why it's wrong here
Nessus is a broad infrastructure vulnerability scanner; its plugins detect host and service flaws but do not fingerprint WordPress plugins, themes and core versions against CMS-specific advisories. It is tempting because it is a well-known vulnerability scanner, yet WordPress component-level known-vulnerability identification needs a dedicated tool such as WPScan.
- ✗
Nikto
Why it's wrong here
Nikto is a web server scanner that flags server misconfigurations and outdated software signatures, but it does not enumerate WordPress core, plugin or theme versions against a vulnerability database. It is tempting because it targets web servers, yet WordPress-specific known-vulnerability identification requires a dedicated scanner such as WPScan.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.