Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:

⚠ Common exam trap

CRISC often tests whether candidates confuse a curated vulnerability list (KEV) with a scanning tool or commercial feed — the trap is assuming any vulnerability-related resource must be a scanner or paid intelligence service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A list of known exploited vulnerabilities maintained by the US government

The CISA Known Exploited Vulnerabilities (KEV) catalog is a publicly maintained list published by the US Cybersecurity and Infrastructure Security Agency (CISA) that enumerates vulnerabilities confirmed to be actively exploited in the wild. It is not a scanning tool, commercial feed, or configuration benchmark — it is a curated reference list used to prioritize patching. Organizations use it to drive remediation deadlines, especially under Binding Operational Directive 22-01 for US federal agencies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An application vulnerability scanning tool

    Why it's wrong here

    The KEV catalog is a curated list of vulnerabilities with confirmed in-the-wild exploitation, not a scanner that probes hosts or code. Scanning tools are tempting because they also identify vulnerabilities, but they discover them through active interrogation, whereas KEV simply enumerates known-exploited CVEs for prioritisation.

  • ✗

    A commercial threat intelligence feed

    Why it's wrong here

    KEV is a free, publicly published US government catalog, not a paid commercial feed with proprietary research or vendor-specific scoring. Commercial feeds are tempting because they also supply threat intelligence and vulnerability context, but KEV's defining characteristic is authoritative, exploitation-confirmed CVE enumeration available to all.

  • ✗

    A configuration vulnerability assessment benchmark

    Why it's wrong here

    KEV lists exploited vulnerabilities by CVE; it does not benchmark configuration settings against hardening baselines such as CIS. Benchmarks are tempting because they also support vulnerability management, but they assess system configuration posture, whereas KEV identifies specific software flaws known to be attacked.

  • ✓

    A list of known exploited vulnerabilities maintained by the US government

    Why this is correct

    The KEV catalog is maintained by the US Cybersecurity and Infrastructure Security Agency, listing vulnerabilities with confirmed exploitation in the wild. It satisfies the stem by providing an authoritative government-sourced feed for prioritising vulnerability identification, rather than a general vulnerability database.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.