Study. uk . com
  1. Home
  2. All questions
  3. Question 59

CompTIA Security+ study material · question 59 of 611

Why does the Known Exploited Vulnerabilities catalog read more like a directive than an advisory list?

  1. Because it supersedes CVSS scoring
  2. Because entries carry a remediation due date binding on US federal agencies
  3. Because entries are removed once patched
  4. Because it is published under a paid subscription
Show the answer

Answer: B. Because entries carry a remediation due date binding on US federal agencies

Each entry has a due date under a binding operational directive, which turns the list into an obligation for those agencies.

Source: CISA Known Exploited Vulnerabilities (KEV) Catalog (CISA) — CISA Known Exploited Vulnerabilities Catalog › Binding Operational Directive 22-01

Challenge yourself on this topic → Study as cards