CS0-003 Vulnerability Management Practice Question
Which of the following best describes the purpose of the CISA Known Exploited Vulnerabilities (KEV) catalog in vulnerability management?
⚠ Common exam trap
CS0-004 often tests the distinction between vulnerability scoring (CVSS), exploitation evidence (KEV), and testing frameworks (PTES), so candidates must not confuse the KEV catalog with severity scoring or penetration testing methodologies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It lists vulnerabilities that are known to have been exploited in the wild
The CISA Known Exploited Vulnerabilities (KEV) catalog is a authoritative list maintained by CISA that enumerates vulnerabilities confirmed to have been exploited in the wild. Its purpose is to help organizations prioritize remediation by focusing on vulnerabilities with active exploitation evidence, not theoretical risk. This makes it a key input for risk-based vulnerability management and for meeting Binding Operational Directive 22-01 requirements for federal agencies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It lists vulnerabilities that are known to have been exploited in the wild
Why this is correct
The CISA KEV catalog's defining criterion is real-world exploitation evidence; CISA adds a CVE only after confirming it has been actively exploited in the wild, which is why federal agencies under Binding Operational Directive 22-01 must remediate KEV-listed vulnerabilities on an accelerated timeline regardless of their CVSS score.
- ✗
It provides a framework for conducting penetration tests
Why it's wrong here
The KEV catalog is not a testing methodology or framework; it contains no guidance on how to plan, scope, or execute a penetration test. It is purely a curated list of CVEs with confirmed exploitation, unrelated to offensive security testing procedures.
- ✗
It provides a scoring system for vulnerability severity
Why it's wrong here
Severity scoring is the function of CVSS, the Common Vulnerability Scoring System, which produces a numeric base score from exploitability and impact metrics. KEV entries deliberately omit a standardized severity score and instead prioritize purely on the binary fact of observed exploitation, which can include even moderate-CVSS vulnerabilities.
- ✗
It offers a database of configuration baselines for operating systems
Why it's wrong here
Configuration baselines are the domain of frameworks like CIS Benchmarks or DISA STIGs, which define secure settings for operating systems and applications. KEV contains no configuration guidance at all; it is exclusively a vulnerability list tied to specific CVE identifiers and exploitation status.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.