CAS-001 · Question #232
Based on the results of a recent audit, a company rolled out a standard computer image in an effort to provide consistent security configurations across all computers. Which of the following…
The correct answer is C. Scan computers weekly against the baseline. Scanning computers weekly against the established baseline directly and continuously compares each machine's current configuration state to the known-good standard image. Any drift - installed software, changed registry keys, modified settings - is immediately detected as a…
Question
Based on the results of a recent audit, a company rolled out a standard computer image in an effort to provide consistent security configurations across all computers. Which of the following controls provides the GREATEST level of certainty that unauthorized changes are not occurring?
Options
- ASchedule weekly vulnerability assessments
- BImplement continuous log monitoring
- CScan computers weekly against the baseline
- DRequire monthly reports showing compliance with configuration and updates
How the community answered
(21 responses)- A5% (1)
- B14% (3)
- C76% (16)
- D5% (1)
Explanation
Scanning computers weekly against the established baseline directly and continuously compares each machine's current configuration state to the known-good standard image. Any drift - installed software, changed registry keys, modified settings - is immediately detected as a deviation. This is the technical control most tightly aligned with detecting unauthorized configuration changes. Option A (vulnerability assessments) identifies security weaknesses but does not specifically compare against a configuration baseline. Option B (continuous log monitoring) is valuable for detecting events but logs can be incomplete or tampered with and do not constitute a direct configuration comparison. Option D (monthly compliance reports) is too infrequent and relies on self-reporting rather than technical verification.
Topics
Community Discussion
No community discussion yet for this question.