Triage BoardGet the app

Domain 2 · Vulnerability Management

Reading the output of vulnerability assessment tools

Vulnerability assessment tools such as Nmap, Nessus and Nuclei print output, and objective 2.2 asks what that output proves: which port is really open, which finding is real, which tool could have produced the result. CS0-004 names six families of tools, from network mappers to breach and attack simulation (BAS) frameworks, and expects you to know what each one can and cannot tell you.

  • Exam code CS0-004
  • Domain weight 26%
  • Tickets here 16

What 2.2 expects you to readNote

  • Recognize each named tool by its job and by the shape of its output.
  • Read raw output (port states, service versions, severity labels, template matches) and say what it proves.
  • Keep three jobs apart: finding a vulnerability, exploiting it, and testing whether your detections fire.
  • Know when a result needs confirming before anyone acts on it.

The six tool families

CS0-004 objective 2.2: the tools it names, the question each answers, the output you are shown
FamilyTools namedQuestion it answersTypical output
Network scanning and mappingAngry IP Scanner, MasscanWhat is alive, and which ports answer, fastLists of IPs and ports
MultipurposeNmap, Metasploit Framework, Maltego, Recon-ngNmap: ports, services, OS. Metasploit: can it be exploited. Maltego, Recon-ng: what is public about the targetPort tables, exploit sessions, entity graphs
Web application scannersBurp Suite, Zed Attack Proxy (ZAP), NiktoWhat a web app exposes or mishandlesRequests, responses, issue lists
Vulnerability scannersNessus, Nuclei, OpenVASWhich known weaknesses a host or service hasFindings with severity, CVE and evidence
Cloud infrastructure assessmentScoutSuite, Prowler, Trivy, CheckovIs the account, image or template configured safelyFailed checks, vulnerable packages, policy hits
Breach and attack simulationAtomic Red Team, CalderaDo detections fire on known MITRE ATT&CK techniquesPass or miss per technique

Compared with the CS0-003 objectives, the CS0-004 objectives (version 2.0) add Masscan, Nuclei, Trivy, Checkov and both BAS tools, and drop Arachni, Pacu and the debuggers (checked October 2026).

Reading an Nmap result

nmapFictional host on a documentation range (RFC 5737)
$ nmap -sS -sV -O -p 1-1024 192.0.2.25Nmap scan report for app.example.com (192.0.2.25)Host is up (0.0041s latency).Not shown: 1019 closed tcp ports (reset)PORT    STATE    SERVICE      VERSION22/tcp  open     ssh          OpenSSH 7.4 (protocol 2.0)80/tcp  open     http         nginx 1.14.0135/tcp filtered msrpc443/tcp open     ssl/http     nginx 1.14.0445/tcp filtered microsoft-dsDevice type: general purposeRunning: Linux 4.X|5.XOS details: Linux 4.15 - 5.8

Lines 8 and 10 say filtered: something between scanner and host dropped the probes, so the real state of those ports is unknown. Lines 6, 7 and 9 are where version-based findings start, and they are only as good as the banner.

What the output proves, line by line

Port states. Nmap reports open, closed or filtered. Open means a service answered. Closed means the host replied that nothing listens there. Filtered means no useful reply came back because a firewall or filter ate the probe. The classic misread is treating filtered as closed.

Flags in the command. -sS is a SYN (half-open) scan, -sT a full TCP connect, -sU UDP, -sV version detection, -O OS detection, -Pn skips host discovery, -p- covers every port, and -A bundles OS and version detection, default scripts and traceroute (Nmap options summary). When a stem shows the command, check what it could not have found. Without -sV there is no version column, and without -sU no UDP service was tested.

Scanner findings. Nessus, OpenVAS and Nuclei report a finding with a severity, usually a CVE identifier, and evidence: a banner, a response, a matched template. A finding built on a version banner alone is weaker than one built on a response only the vulnerable code would give, because vendors often backport fixes without changing the version string. The gap between the two is where false positives and false negatives come from.

Severity labels. The severity a scanner prints comes from the Common Vulnerability Scoring System (CVSS). Check which version: a v4.0 vector has different metric groups from a v3.1 one, as laid out in CVSS 4.0 vs 3.1.

Cloud and container output. ScoutSuite audits configuration across cloud providers. Prowler runs best-practice and compliance checks on AWS, Azure and Google Cloud. Trivy scans container images and infrastructure as code (IaC) and can produce a software bill of materials. Checkov analyzes IaC files before deployment. Their output ties a failed check or a vulnerable package to a resource, an image layer or a line in a template, so you can see where the fix belongs.

Find, exploit, emulateTrap

Three kinds of tool answer three different questions. Nessus, OpenVAS and Nuclei find known weaknesses. The Metasploit Framework exploits one to prove impact. Atomic Red Team and MITRE Caldera emulate adversary techniques to test the defenses, and they never look for a missing patch. Distractors swap these freely.

Output-reading tickets

Exhibits lead here: work out what the scan table or scanner line proves, then match that to an option.

Ticket 1 / 16

0 right

INC-001

During a security assessment, an analyst wants to test the rules configured on a firewall by sending specifically crafted packets to the network. Which type of packet should the analyst use?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AUDP probes find UDP services; because UDP has no handshake flags, they say little about how a firewall filters TCP.
  2. BThere is no 'connect' packet; a TCP connect scan completes the full handshake to find open ports and does not map firewall rules.
  3. CCorrect: An ACK scan (Nmap -sA) sends unsolicited ACK packets; an RST reply means the port is unfiltered and no reply means filtered, which maps the firewall rules.
  4. DA SYN scan finds open, closed, or filtered ports on the target, but it is not the specific technique for mapping stateful firewall rules.

INC-002

A cybersecurity analyst is tasked with checking for open network ports on a server to assess potential vulnerability. Which tool could the analyst use to perform this task?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AMetasploit exploits vulnerabilities; it can call a port scan, but it is not the standard port-discovery tool.
  2. BBurp Suite tests web applications through an intercepting proxy; it does not scan a server's network ports.
  3. CCorrect: Nmap probes hosts to find open ports, running services and versions, and often the operating system.
  4. DWireshark passively captures and analyzes traffic; it does not probe a server for open ports.

INC-003

Which of the following tools is an open-source platform used for comprehensive software vulnerability scanning and assessment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ABurp Suite is a commercial web application testing proxy (with a free Community edition), so it is neither open source nor a general vulnerability scanner.
  2. BNmap discovers hosts, ports, and services; its scripts can check some vulnerabilities, but it is not a full vulnerability assessment platform.
  3. CCorrect: OpenVAS is the open-source scanner (part of Greenbone) that runs a large feed of vulnerability tests against hosts and services.
  4. DWireshark analyzes captured network traffic; it does not scan for vulnerabilities.

INC-004

A network administrator wants to perform a security test on their internal network. They need a tool that can scan for vulnerabilities in network services, identify outdated software versions, and check for configuration flaws. Which tool could the administrator use?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AWireshark captures and analyzes packets but does not test services for vulnerabilities or misconfigurations.
  2. BCorrect: Nessus is a vulnerability scanner that checks network services for known vulnerabilities, outdated versions, and configuration weaknesses.
  3. CTrueCrypt was a disk encryption tool, now discontinued, and has nothing to do with scanning.
  4. DKali Linux is a distribution that bundles many tools, so it is a platform and no specific vulnerability scanner.

INC-005

What is the primary purpose of vulnerability correlation in an enterprise vulnerability management program?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ACompliance reporting uses vulnerability data, but producing auditor reports is not the purpose of correlation.
  2. BPrioritizing by CVSS alone ignores context, and correlation is about linking findings instead of ranking them by one score.
  3. CAssigning tasks to people is workflow management, which comes after findings are understood and prioritized.
  4. DCorrect: Correlation links findings across systems to reveal shared weaknesses, such as one bad image or configuration baseline, so the root cause can be fixed once.

INC-006

Review the merged vulnerability scanner output. After normalizing duplicates and applying asset tags, which remediation action should be performed first?

Exhibit

AssetCVECVSSScan SourceEvidence Level
DB-01CVE-20XX-12349.8AgentHigh
DB-01CVE-20XX-12347.5NetworkMedium
Web-02CVE-20XX-56788.2AgentlessHigh
App-03CVE-20XX-90126.4NetworkLow

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ATreating the two DB-01 records as separate issues double-counts one vulnerability; duplicates should be merged.
  2. BCorrect: After the DB-01 duplicates are merged, the high-confidence agent result (CVSS 9.8) wins over the weaker network result, making it the top-priority fix.
  3. CLow evidence lowers confidence in the App-03 finding, which argues for verifying it before anyone fixes it first.
  4. DSorting raw findings by CVSS without merging duplicates or considering evidence quality ignores the normalization the scenario asks for.

INC-007

Review the scanner evidence. Which finding requires immediate credentialed validation because the evidence string indicates a probable true positive?

Exhibit

HostCVEEvidence
app01CVE-20XX-1111Version string matches vulnerable build 4.2.1
app02CVE-20XX-2222Port 443 open; banner shows patched build
db01CVE-20XX-3333Service responded to non-credentialed probe
web01CVE-20XX-4444No evidence returned; plugin timed out

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AThe banner on app02 shows a patched build, so this finding is probably a false positive and cannot be called a probable true positive.
  2. BCorrect: A version string that matches a known vulnerable build is strong evidence, so app01 should get credentialed validation right away to confirm it, for example to rule out a backported patch.
  3. CA service answering a non-credentialed probe proves only that it is reachable; vulnerability is still unproven.
  4. DA timed-out plugin gave no evidence at all, so this result is inconclusive rather than a probable true positive.

INC-008

Credentialed and non-credentialed scans of the same host show differing findings. Which findings are likely false positives and what validation is required?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ARemediating every non-credentialed finding without verification wastes effort on false positives.
  2. BCorrect: Non-credentialed scans guess from banners and responses, so remote RCE findings that the credentialed scan does not confirm should be checked with a credentialed rescan and configuration review.
  3. CA high CVSS score says how serious a vulnerability would be and says nothing about whether a non-credentialed detection is accurate.
  4. DThe two modes differ in accuracy; credentialed results are more reliable, so results that conflict need verification.

INC-009

A high-severity finding on an OT-tagged asset shows a false-positive rate above 60 percent in prior scans. Which decision path correctly minimizes false positives while ensuring timely remediation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AWaiting a year leaves a high-severity finding unaddressed, which breaks remediation SLAs.
  2. BEmergency patching of an OT asset based on an often-wrong finding risks outages in a safety-critical environment.
  3. CAnother non-credentialed scan reproduces the same false-positive problem, and more aggressive scans can disrupt fragile OT devices.
  4. DCorrect: Credentialed verification during a planned maintenance window confirms the finding safely, and only then is it escalated for remediation.

INC-010

Given the container image scan below, which instruction requires the image to be rebuilt with an updated upstream source to remediate the critical vulnerability?

Exhibit

Layer IDInstructionScanner FindingCVE Severity
L1FROM alpine:3.14libcrypto vulnerabilityCritical
L2RUN apk add --no-cache python3NoneNone
L3COPY . /appNoneNone
L4RUN pip install -r requirements.txtrequests library CVEHigh

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ARebuilding with updated pip requirements fixes the High-severity requests library CVE in L4 but leaves the Critical libcrypto flaw in the base layer.
  2. BThe apk add layer had no findings; it installs Python and does not contain the vulnerable libcrypto.
  3. CCorrect: The Critical libcrypto flaw comes from the alpine:3.14 base image, so the FROM line must point to a patched, newer base image and the image must be rebuilt.
  4. DThe COPY layer adds application files and had no findings, so changing it does not fix the base-image vulnerability.

INC-011

Given container image scan results, which finding should receive the highest remediation priority?

Exhibit

ImageCVEExploit MaturityRuntime PackageExposure
app:v1.2CVE-20XX-1234MatureYesPublic
app:v1.2CVE-20XX-5678NoneNoInternal
db:v3.0CVE-20XX-9012Proof-of-ConceptYesInternal

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACVSS alone ignores exploit maturity, whether the package actually runs, and exposure, which are the facts that set real priority.
  2. BA proof-of-concept exploit on an internal system is a real concern, but it is less urgent than a mature exploit on a public-facing runtime package.
  3. CCorrect: A mature exploit for a package that is loaded at runtime in a publicly exposed image is the most likely to be exploited, so it gets top priority.
  4. DNo known exploit, a package not used at runtime, and internal-only exposure make this the lowest priority.

INC-012

Review the Cloud Security Posture Management alerts below. Which instance represents the most critical risk path requiring immediate containment?

Exhibit

InstanceCVSS ScoreAttached IAM PermissionsIngress Rules
Web-019.8S3ReadOnlyAccess0.0.0.0/0 on 443
Data-017.5AdministratorAccess0.0.0.0/0 on 443
App-029.8DynamoDBRead10.0.0.0/8 on 8080
Queue-015.3SQSFullAccess10.0.0.0/8 on 22

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AApp-02 has a 9.8 CVSS score, but it is reachable only from the internal network and has read-only DynamoDB rights, so the attack path is weaker.
  2. BCorrect: Data-01 is internet-facing and has AdministratorAccess, so exploiting even a 7.5 vulnerability could give an attacker control of the whole cloud account.
  3. CQueue-01 has the lowest score and is reachable only internally, even though SSH is open.
  4. DWeb-01 is internet-facing with a 9.8 score, but its read-only S3 permission limits what an attacker can do after compromise.

INC-013

Which of the following is the most significant limitation of using only automated vulnerability scanning tools?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAutomated scanning usually costs less than manual testing, which is why organizations use it widely.
  2. BCorrect: Scanners find known issues by signature or rule, but they cannot understand business logic, so flaws like broken workflows or authorization logic errors need human testing.
  3. CModern scanners have extensive reporting features, so reporting is not their key limitation.
  4. DWireless assessment tools exist, and wireless coverage is a scope choice instead of the main limitation of automation.

INC-014

An analyst runs Nuclei against a staging web app and gets this line: [git-config] [http] [medium] https://staging.example.com/.git/config. What does the finding mean?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANuclei detects with templates; the line reports a match, not that the repository was downloaded.
  2. BThe template checks for an exposed config file over HTTP, not for a vulnerable Git server version.
  3. CCorrect: Nuclei reports which template matched, the protocol, its severity and the URL where the match occurred.
  4. DNothing in the output mentions credentials; it shows only that the config file can be reached.

INC-015

Before deployment, a CI pipeline must flag a vulnerable OS package in a container image and an open security group in a Terraform file. Which single tool covers both checks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AScoutSuite audits the configuration of live cloud accounts; it does not scan images or Terraform in a pipeline.
  2. BCorrect: Trivy scans container images for vulnerable packages and IaC files such as Terraform for misconfigurations.
  3. CNikto checks running web servers for known issues; it does not read container images or IaC files.
  4. DRecon-ng is a reconnaissance framework for open-source intelligence, not an image or IaC scanner.

INC-016

After tuning EDR rules, a SOC wants to run small scripted tests mapped to MITRE ATT&CK techniques on a lab host to confirm the alerts fire. Which tool is built for this?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Atomic Red Team is a library of small tests mapped to ATT&CK techniques, used to check that detections fire.
  2. BNessus finds vulnerabilities and misconfigurations; it does not emulate adversary techniques to test detections.
  3. CMetasploit is built to exploit vulnerabilities; its modules are not a library of ATT&CK-mapped detection tests.
  4. DOpenVAS is a vulnerability scanner, so it reports weaknesses rather than exercising detection rules.

Shift tally

0 / 0

Asked about the 2.2 tool list

Do I need to memorize Nmap flags?

Learn the common ones well enough to read a command: -sS, -sT, -sU, -sV, -O, -Pn, -p- and -A. Objective 2.2 is a given a scenario objective (CS0-004 objectives, version 2.0, checked October 2026), so expect output to interpret more than definitions to recite.

Which tools do I need that CS0-003 didn't list?

CS0-004 adds Masscan, Nuclei, Trivy, Checkov, Atomic Red Team and Caldera, and no longer lists Arachni, Pacu, Immunity Debugger or GDB (CompTIA CS0-003 and CS0-004 objectives, checked October 2026). The rest of the version differences are on CS0-004 vs CS0-003.

What do I do with a finding once the tool reports it?

You confirm it, then rank it against the others on exploitability, exposure and asset value. That step is objective 2.3, covered in prioritizing and mitigating vulnerabilities.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.