Study. uk . com
  1. Home
  2. All questions
  3. Question 72

CISSP study material · question 72 of 500

A vulnerability management team wants to pull the CISA Known Exploited Vulnerabilities catalog into its scanner automatically each morning and to give priority to flaws that attackers have used in ransomware campaigns. Which two published features of the catalog support this? Choose two.

  1. A vendor-supplied patch package attached to each record for direct deployment by the scanner
  2. A per-record indication of whether the weakness has appeared in known ransomware campaigns
  3. A per-record CVSS base score that orders the catalog by technical severity for the subscriber
  4. Machine-readable CSV and JSON downloads of the full catalog published alongside the web listing
Show the answer

Answer: D. Machine-readable CSV and JSON downloads of the full catalog published alongside the web listing
B. A per-record indication of whether the weakness has appeared in known ransomware campaigns

CISA publishes the catalog as CSV and JSON beside the web listing and tags each record for ransomware use; it distributes no patches and does not rank entries by score.

Source: CISA Known Exploited Vulnerabilities Catalog (CISA) — Known Exploited Vulnerabilities Catalog > page header and entry fields

Challenge yourself on this topic → Study as cards