Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

A vulnerability management team is prioritizing remediation of a list of vulnerabilities. They want to incorporate the likelihood of exploitation based on real-world exploit activity. Which of the following data sources should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EPSS

The Exploit Prediction Scoring System (EPSS) uses real-world exploit data to predict the likelihood of exploitation. KEV lists known exploited vulnerabilities but is not a scoring system. CVSS and CVE are not probabilistic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CVE

    Why it's wrong here

    Common Vulnerabilities and Exposures (CVE) is a standardized dictionary of publicly known cybersecurity vulnerabilities. While it assigns unique identifiers to document security flaws, it does not provide any scoring mechanism, risk metrics, or predictive analysis to help teams prioritize remediation based on threat likelihood.

  • ✗

    CVSS

    Why it's wrong here

    The Common Vulnerability Scoring System (CVSS) evaluates the principal characteristics of a vulnerability to produce a numerical score representing its technical severity. However, CVSS is static and fails to account for real-world threat landscapes or the dynamic probability of a vulnerability being actively exploited in the wild.

  • ✗

    KEV

    Why it's wrong here

    CISA's Known Exploited Vulnerabilities (KEV) catalog is an invaluable repository of vulnerabilities that have been confirmed to be actively exploited in the wild. While it is crucial for immediate patching decisions, it functions as a binary list of historical and current exploits rather than a predictive model that calculates the future probability of exploitation for unexploited flaws.

  • ✓

    EPSS

    Why this is correct

    The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability, ranging from 0 to 1, that a software vulnerability will be exploited in the wild within the next 30 days. By combining real-world threat intelligence with machine learning, EPSS allows security analysts to prioritize remediation efforts based on actual threat likelihood rather than theoretical severity alone.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.