nerdexam
CompTIA

CAS-002 · Question #258

During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. The audit…

The correct answer is A. The devices are being modified and settings are being overridden in production. Configuration drift occurs when production systems are modified after initial hardening, causing settings to deviate from the compliant baseline over time.

Enterprise Security

Question

During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. The audit discovers that 40% of the desktops do not meet requirements. Which of the following is the cause of the noncompliance?

Options

  • AThe devices are being modified and settings are being overridden in production.
  • BThe patch management system is causing the devices to be noncompliant after issuing the
  • CThe desktop applications were configured with the default username and password.
  • D40% of the devices have been compromised.

How the community answered

(20 responses)
  • A
    80% (16)
  • B
    5% (1)
  • C
    10% (2)
  • D
    5% (1)

Why each option

Configuration drift occurs when production systems are modified after initial hardening, causing settings to deviate from the compliant baseline over time.

AThe devices are being modified and settings are being overridden in production.Correct

Even when devices are properly hardened before deployment, users, administrators, or applications can alter OS-level settings post-deployment, causing gradual configuration drift away from the compliant baseline. Without continuous compliance monitoring and automated enforcement, these accumulated changes result in a significant portion of the fleet falling out of compliance. The six-month gap between deployment and the audit is consistent with drift caused by ongoing production modifications rather than a deployment-time error.

BThe patch management system is causing the devices to be noncompliant after issuing the

Patch management systems apply software updates but do not typically override OS-level hardening settings unless a specific patch explicitly changes security configuration values.

CThe desktop applications were configured with the default username and password.

Default credentials on desktop applications would represent an error present at initial deployment, not explain why devices that were initially compliant subsequently became non-compliant six months later.

D40% of the devices have been compromised.

If 40 percent of devices had been compromised, the audit would likely detect security indicators and anomalies well beyond mere non-compliance with configuration hardening requirements.

Concept tested: Configuration drift and continuous compliance monitoring

Source: https://csrc.nist.gov/publications/detail/sp/800-128/final

Topics

#compliance drift#configuration management#OS hardening#audit

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice