Objective 2.3CS0-003

2.3 Given a scenario, analyze data to prioritize vulnerabilities.

Objective 2.3 sits in Vulnerability Management, which carries 30% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-3Vulnerability ManagementModerate

Your team wants an authoritative list of CVEs actually being exploited in the wild to drive patch order. Which resource is that?

The full NVD CVE feedThe full CVE feed lists everything published, exploited or not.
Vendor press releasesVendor advisories cover their own products and vary in rigor.
The CISA KEV catalogCorrect · your answerCorrect: the KEV catalog is the authoritative exploited-in-the-wild list.
An internal pentest reportA pentest shows what one tester reached, not global adversary activity.

Correct.

Concept

Most published vulnerabilities never see real attacks, so a prioritization signal built on observed adversary activity separates the vulnerabilities causing harm now from the long tail.

Why C

CISA maintains the Known Exploited Vulnerabilities catalog as the authoritative source of vulnerabilities that have been exploited in the wild and recommends prioritizing their remediation.

#kev#prioritization#vulnerability-management

Now you: objective 2.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-3Vulnerability ManagementHard

An analyst asks why a wormable vulnerability with a public PoC is absent from the KEV catalog. What is the most likely reason?

Sample question 2 of 3

2-3Vulnerability ManagementModerate

Your team builds its prioritization framework and wants exploitation status as an input, the way SSVC uses it. What does CISA say the KEV catalog provides?

Sample question 3 of 3

2-3Vulnerability ManagementModerate

An analyst finds a KEV-listed product in the environment is end-of-life with no patch available. Which remediation action does CISA's directive prescribe?

Full CySA+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Vulnerability Management