- Home
- All questions
- Question 59
CompTIA Security+ study material · question 59 of 611
Why does the Known Exploited Vulnerabilities catalog read more like a directive than an advisory list?
Show the answer
Answer: B. Because entries carry a remediation due date binding on US federal agencies
Each entry has a due date under a binding operational directive, which turns the list into an obligation for those agencies.
Source: CISA Known Exploited Vulnerabilities (KEV) Catalog (CISA) — CISA Known Exploited Vulnerabilities Catalog › Binding Operational Directive 22-01