CAS-003 · Question #668
An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks. When the engineer opens a file in a…
The correct answer is C. SCAP. SCAP (Security Content Automation Protocol) is a NIST-maintained framework that standardizes the format and language for expressing security configuration checklists, vulnerability data, and compliance results. It includes component specifications such as XCCDF (eXtensible…
Question
An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks. When the engineer opens a file in a text editor, the following excerpt appears:
Which of the following capabilities would a configuration compliance checker need to support to interpret this file?
Exhibit
Options
- ANessus
- BSwagger file
- CSCAP
- DNetcat
- EWSDL
How the community answered
(62 responses)- B5% (3)
- C92% (57)
- D2% (1)
- E2% (1)
Explanation
SCAP (Security Content Automation Protocol) is a NIST-maintained framework that standardizes the format and language for expressing security configuration checklists, vulnerability data, and compliance results. It includes component specifications such as XCCDF (eXtensible Configuration Checklist Description Format) and OVAL (Open Vulnerability and Assessment Language), which are XML-based formats used to define and orchestrate OS security configuration checks. A SCAP-compliant scanner can parse these files to automate compliance assessments against CIS Benchmarks or STIGs. Nessus is a vulnerability scanner (a tool, not a file format), Swagger/WSDL are API definition formats, and Netcat is a network utility.
Topics
Community Discussion
No community discussion yet for this question.
