Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1. What is a Known Exploited Vulnerability?
Any vulnerability with a long description
A vulnerability that only exists in theory
A vulnerability with evidence of real-world exploitation
A vulnerability that never affects production systems
2. Why does KEV status matter for prioritization?
It signals that exploitation is already happening in the real world
It guarantees the asset is internet-facing
It means no patch testing is needed
It replaces asset inventory
3. What should teams combine with KEV status to make better decisions?
Guesswork only
Marketing claims
The age of the ticket title
Asset exposure, business criticality, ownership, and compensating controls
4. What is one major purpose of the CISA KEV Catalog?
To teach exploit development
To identify vulnerabilities known to be exploited and support defensive prioritization
To replace all vulnerability management tools
To certify that a system is secure
5. What is often the hardest operational step in KEV remediation?
Ignoring product versions
Removing all owners
Matching KEV entries to accurate asset and software inventory
Assuming every system is affected
6. What should happen when immediate patching is not possible?
Close the ticket with no action
Hide the finding from reports
Claim the risk is gone
Apply approved mitigations, document the exception, monitor, and plan durable remediation
7. What does verification prove in a KEV workflow?
That remediation or mitigation was actually completed and confirmed
That no evidence is needed
That every scanner result is automatically perfect
That ownership no longer matters
8. Which is the best KEV operating routine?
Wait, guess, and patch randomly
Ingest KEV data, match assets, enrich risk context, assign owners, remediate or mitigate, verify, report, and improve
Ignore active exploitation and sort only by ticket age
Use KEV status to learn exploitation techniques
Submit Quiz
Previous