CRISC IT Risk Identification Practice Question
Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?
⚠ Common exam trap
The trap is confusing the NVD with the CISA KEV catalog; both are government-related vulnerability databases, but only KEV specifically lists vulnerabilities known to be exploited in the wild.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CISA KEV
The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and lists vulnerabilities that have been exploited in the wild. It is a government-maintained threat intelligence source specifically focused on known exploited vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OSINT
Why it's wrong here
OSINT is any publicly available information, not a government-maintained catalogue of exploited vulnerabilities. It is tempting because OSINT feeds often aggregate such data, and it would be correct when the requirement is broad, uncurated collection from public sources rather than an authoritative government list.
- ✗
NVD
Why it's wrong here
The NVD is a vulnerability database, but it is maintained by NIST and lists CVEs rather than specifically known exploited vulnerabilities. It is tempting because it is government-run, and NVD would be correct when the requirement is severity scoring and CVE enrichment rather than an actively exploited vulnerability catalogue.
- ✓
CISA KEV
Why this is correct
The CISA Known Exploited Vulnerabilities catalogue is maintained by the US Cybersecurity and Infrastructure Security Agency and lists vulnerabilities with confirmed in-the-wild exploitation, satisfying the stem's government-maintained, known-exploited requirement. Other sources, such as vendor advisories or commercial feeds, lack that specific provenance.
- ✗
ISACs
Why it's wrong here
ISACs are sector-specific information sharing bodies, typically industry-run, not a government-maintained vulnerability catalogue. They are tempting because they distribute threat intelligence, and an ISAC would be correct when the need is sector-specific indicators and peer sharing rather than a national exploited-vulnerability list.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.