CAS-001 · Question #521
During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. Theaudit…
The correct answer is A. The devices are being modified and settings are being overridden in production. The desktops were hardened at deployment time, meaning the initial configuration was compliant. Six months later, 40% are out of compliance. The most logical explanation is that settings were changed or overridden after deployment - users, applications, or administrators…
Question
During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. Theaudit discovers that 40% of the desktops do not meet requirements. Which of the following is the cause of the noncompliance?
Options
- AThe devices are being modified and settings are being overridden in production.
- BThe patch management system is causing the devices to be noncompliant after issuing the latest
- CThe desktop applications were configured with the default username and password.
- D40% of the devices have been compromised.
How the community answered
(27 responses)- A85% (23)
- B4% (1)
- C4% (1)
- D7% (2)
Explanation
The desktops were hardened at deployment time, meaning the initial configuration was compliant. Six months later, 40% are out of compliance. The most logical explanation is that settings were changed or overridden after deployment - users, applications, or administrators modified the OS-level configurations that the hardening established. This is a common operational security problem: point-in-time hardening degrades without continuous compliance enforcement (e.g., via a configuration management tool or SIEM). Option B (patch management causing noncompliance) is possible but not the most likely culprit given the hardening focus. Option C (default credentials) does not explain why previously hardened devices became noncompliant over time. Option D (40% compromised) is an extreme assumption unsupported by the scenario.
Topics
Community Discussion
No community discussion yet for this question.