Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

Which tool is specifically designed for scanning WordPress websites to detect vulnerabilities, such as outdated plugins, themes, and weak passwords?

⚠ Common exam trap

It's easy for candidates to confuse general web vulnerability scanners (like Nikto or OpenVAS) with a CMS-specific tool, assuming any scanner can perform WordPress vulnerability detection, but only WPScan is purpose-built for WordPress enumeration and exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPScan

WPScan is a dedicated WordPress security scanner that enumerates WordPress-specific vulnerabilities, including outdated plugins, themes, and weak passwords via XML-RPC brute-force testing. It uses the WordPress vulnerability database (wpvulndb.com) to match installed versions against known CVEs, making it the correct tool for this targeted task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OpenVAS

    Why it's wrong here

    OpenVAS performs broad network and host vulnerability assessment via its feed of NVTs; it lacks WordPress-aware plugin, theme and credential enumeration. It is tempting because OpenVAS does scan web services for known CVEs, but WPScan is the tool specifically designed for WordPress vulnerability detection and would be correct for this scenario.

  • ✗

    Nikto

    Why it's wrong here

    Nikto performs generic web server scanning for misconfigurations and outdated server software; it does not enumerate WordPress plugins, themes or brute-force wp-login credentials. It is tempting because Nikto targets web servers, but WPScan is purpose-built for WordPress-specific vulnerability detection and would be the correct choice here.

  • ✓

    WPScan

    Why this is correct

    WPScan is a dedicated WordPress vulnerability scanner that enumerates installed plugins, themes and users, then checks them against known vulnerability databases and tests for weak credentials. Generic web scanners lack this WordPress-specific enumeration and detection logic.

  • ✗

    Nessus

    Why it's wrong here

    Nessus is a general-purpose vulnerability scanner that enumerates CVEs across hosts and services; it does not fingerprint WordPress plugin versions, theme files or wp-login credentials. It is tempting because Nessus does include some web checks, but WPScan is purpose-built for WordPress-specific enumeration and would be the correct choice here.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.