nerdexam
CompTIA

CAS-003 · Question #303

A Chief Information Security Officer (CISO is reviewing and revising system configuration and hardening guides that were developed internally and have been used several years to secure the…

The correct answer is A. CVE database. Tests knowledge of the best reference source for revising and updating multi-year-old system hardening guides.

Enterprise Security Operations

Question

A Chief Information Security Officer (CISO is reviewing and revising system configuration and hardening guides that were developed internally and have been used several years to secure the organization's systems. The CISO knows improvements can be made to the guides. Which of the following would be the BEST source of reference during the revision process?

Options

  • ACVE database
  • BInternal security assessment reports
  • CIndustry-accepted standards
  • DExternal vulnerability scan reports
  • EVendor-specific implementation guides

How the community answered

(23 responses)
  • A
    96% (22)
  • B
    4% (1)

Why each option

Tests knowledge of the best reference source for revising and updating multi-year-old system hardening guides.

ACVE databaseCorrect

The CVE database is a continuously updated, authoritative repository of publicly disclosed vulnerabilities. When revising hardening guides that are several years old, referencing CVEs allows the CISO to identify vulnerabilities discovered since the guides were originally written and ensure that system configurations actively mitigate current, specific threats that were not known when the original guides were created.

BInternal security assessment reports

Internal security assessment reports reflect the organization's own historical findings and do not provide the broad, industry-wide vulnerability data needed to comprehensively improve hardening baselines.

CIndustry-accepted standards

Industry-accepted standards offer useful general configuration baselines but are updated infrequently and may not address the specific newly discovered vulnerabilities that a revised hardening guide should mitigate.

DExternal vulnerability scan reports

External vulnerability scan reports capture the organization's current exposure at a single point in time but are not a comprehensive reference for systematically revising hardening procedures across all systems.

EVendor-specific implementation guides

Vendor-specific implementation guides focus on product feature configuration and deployment procedures, not on addressing the full spectrum of security vulnerabilities relevant to system hardening.

Concept tested: CVE database as system hardening revision reference

Source: https://www.cve.org/About/Overview

Topics

#system hardening#configuration baselines#CVE database#security guides

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice