CRISC IT Risk Identification Practice Question
An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:
⚠ Common exam trap
CRISC often tests whether candidates confuse a curated vulnerability list (KEV) with a scanning tool or commercial feed — the trap is assuming any vulnerability-related resource must be a scanner or paid intelligence service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of known exploited vulnerabilities maintained by the US government
The CISA Known Exploited Vulnerabilities (KEV) catalog is a publicly maintained list published by the US Cybersecurity and Infrastructure Security Agency (CISA) that enumerates vulnerabilities confirmed to be actively exploited in the wild. It is not a scanning tool, commercial feed, or configuration benchmark — it is a curated reference list used to prioritize patching. Organizations use it to drive remediation deadlines, especially under Binding Operational Directive 22-01 for US federal agencies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An application vulnerability scanning tool
Why it's wrong here
The KEV catalog is a curated list of vulnerabilities with confirmed in-the-wild exploitation, not a scanner that probes hosts or code. Scanning tools are tempting because they also identify vulnerabilities, but they discover them through active interrogation, whereas KEV simply enumerates known-exploited CVEs for prioritisation.
- ✗
A commercial threat intelligence feed
Why it's wrong here
KEV is a free, publicly published US government catalog, not a paid commercial feed with proprietary research or vendor-specific scoring. Commercial feeds are tempting because they also supply threat intelligence and vulnerability context, but KEV's defining characteristic is authoritative, exploitation-confirmed CVE enumeration available to all.
- ✗
A configuration vulnerability assessment benchmark
Why it's wrong here
KEV lists exploited vulnerabilities by CVE; it does not benchmark configuration settings against hardening baselines such as CIS. Benchmarks are tempting because they also support vulnerability management, but they assess system configuration posture, whereas KEV identifies specific software flaws known to be attacked.
- ✓
A list of known exploited vulnerabilities maintained by the US government
Why this is correct
The KEV catalog is maintained by the US Cybersecurity and Infrastructure Security Agency, listing vulnerabilities with confirmed exploitation in the wild. It satisfies the stem by providing an authoritative government-sourced feed for prioritising vulnerability identification, rather than a general vulnerability database.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.