nerdexam
Cisco

350-201(NEW-127Q) · Question #19

A data center that manages sensitive government data must enhance its system hardening procedures to counter advanced cyber threats and adhere to federal security regulations. The Chief Technical…

The correct answer is C. Center for Internet Security (CIS) Benchmarks, DISA STIGs (Security Technical Implementation Guides) for Linux and Windows, and NIST SP 800 series. Option C is correct because government data centers managing sensitive information must consult authoritative, federally recognized frameworks: CIS Benchmarks provide detailed, platform-specific hardening checklists; DISA STIGs are mandatory baselines for Department of Defense…

Infrastructure Security and System Hardening

Question

A data center that manages sensitive government data must enhance its system hardening procedures to counter advanced cyber threats and adhere to federal security regulations. The Chief Technical Officer (CTO) is seeking detailed, technical resources for guidance. The data center uses a combination of Linux servers, Windows-based systems, and virtualized network functions. Which specific technical resources should the CTO consult for comprehensive standards and recommendations on system hardening?

Options

  • Aonly the data center's existing security policies, avoiding any external standards or frameworks
  • Bexclusive reliance on built-in security recommendations from the Linux and Windows operating systems, without external references
  • CCenter for Internet Security (CIS) Benchmarks, DISA STIGs (Security Technical Implementation Guides) for Linux and Windows, and NIST SP 800 series
  • Dgeneral online tech community forums, standard user manuals for Linux and Windows, and basic virtualization security guides

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    76% (22)
  • D
    14% (4)

Explanation

Option C is correct because government data centers managing sensitive information must consult authoritative, federally recognized frameworks: CIS Benchmarks provide detailed, platform-specific hardening checklists; DISA STIGs are mandatory baselines for Department of Defense systems and widely adopted across federal environments; and the NIST SP 800 series (especially SP 800-53 and SP 800-123) provides the broader security control standards that federal compliance requires.

  • Option A is wrong because relying solely on internal policies ignores proven external standards and fails to meet federal regulatory requirements like FISMA.
  • Option B is wrong because built-in OS recommendations are general-purpose, not hardening-focused, and lack the depth and compliance alignment needed for sensitive government systems.
  • Option D is wrong because community forums and basic user manuals carry no authoritative weight, are unvetted, and would not satisfy any federal security mandate.

Memory tip: Think "CDN for government hardening" - CIS Benchmarks (configuration baselines), DISA STIGs (DoD-mandated technical guides), and NIST SP 800 (the federal policy backbone). If it's a government data center, you need all three.

Topics

#System Hardening#Security Standards#Compliance Frameworks#NIST/CIS/STIG

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice