Which of the following best describes the purpose of the CISA Known Exploited Vulnerabilities (KEV) catalog in vulnerability management?
The CISA KEV catalog's defining criterion is real-world exploitation evidence; CISA adds a CVE only after confirming it has been actively exploited in the wild, which is why federal agencies under Binding Operational Directive 22-01 must remediate KEV-listed vulnerabilities on an accelerated timeline regardless of their CVSS score.
Why this answer
The CISA Known Exploited Vulnerabilities (KEV) catalog is a authoritative list maintained by CISA that enumerates vulnerabilities confirmed to have been exploited in the wild. Its purpose is to help organizations prioritize remediation by focusing on vulnerabilities with active exploitation evidence, not theoretical risk. This makes it a key input for risk-based vulnerability management and for meeting Binding Operational Directive 22-01 requirements for federal agencies.
Exam trap
CS0-004 often tests the distinction between vulnerability scoring (CVSS), exploitation evidence (KEV), and testing frameworks (PTES), so candidates must not confuse the KEV catalog with severity scoring or penetration testing methodologies.
How to eliminate wrong answers
Option B is wrong because penetration testing frameworks are methodologies like PTES, OWASP Testing Guide, or MITRE ATT&CK, not the KEV catalog. Option C is wrong because vulnerability severity scoring is provided by systems like CVSS (Common Vulnerability Scoring System), not KEV. Option D is wrong because configuration baselines are published by CIS Benchmarks, DISA STIGs, or NIST, not the KEV catalog.