CS0-003 Vulnerability Management Practice Question
A vulnerability management team is prioritizing remediation of a list of vulnerabilities. They want to incorporate the likelihood of exploitation based on real-world exploit activity. Which of the following data sources should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EPSS
The Exploit Prediction Scoring System (EPSS) uses real-world exploit data to predict the likelihood of exploitation. KEV lists known exploited vulnerabilities but is not a scoring system. CVSS and CVE are not probabilistic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CVE
Why it's wrong here
Common Vulnerabilities and Exposures (CVE) is a standardized dictionary of publicly known cybersecurity vulnerabilities. While it assigns unique identifiers to document security flaws, it does not provide any scoring mechanism, risk metrics, or predictive analysis to help teams prioritize remediation based on threat likelihood.
- ✗
CVSS
Why it's wrong here
The Common Vulnerability Scoring System (CVSS) evaluates the principal characteristics of a vulnerability to produce a numerical score representing its technical severity. However, CVSS is static and fails to account for real-world threat landscapes or the dynamic probability of a vulnerability being actively exploited in the wild.
- ✗
KEV
Why it's wrong here
CISA's Known Exploited Vulnerabilities (KEV) catalog is an invaluable repository of vulnerabilities that have been confirmed to be actively exploited in the wild. While it is crucial for immediate patching decisions, it functions as a binary list of historical and current exploits rather than a predictive model that calculates the future probability of exploitation for unexploited flaws.
- ✓
EPSS
Why this is correct
The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability, ranging from 0 to 1, that a software vulnerability will be exploited in the wild within the next 30 days. By combining real-world threat intelligence with machine learning, EPSS allows security analysts to prioritize remediation efforts based on actual threat likelihood rather than theoretical severity alone.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.