nerdexam
CompTIA

CAS-003 · Question #93

During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. The audit…

The correct answer is A. The devices are being modified and settings are being overridden in production. The question states that all hosts are hardened at the OS level before deployment. So we know the desktops are fully patched when the users receive them. Six months later, the desktops do not meet the compliance standards. The most likely explanation for this is that the users…

Enterprise Security Operations

Question

During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations. The audit discovers that 40 percent of the desktops do not meet requirements. Which of the following is the MOST likely cause of the noncompliance?

Options

  • AThe devices are being modified and settings are being overridden in production.
  • BThe patch management system is causing the devices to be noncompliant after issuing the latest
  • CThe desktop applications were configured with the default username and password.
  • D40 percent of the devices use full disk encryption.

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    11% (3)
  • D
    4% (1)

Explanation

The question states that all hosts are hardened at the OS level before deployment. So we know the desktops are fully patched when the users receive them. Six months later, the desktops do not meet the compliance standards. The most likely explanation for this is that the users have changed the settings of the desktops during the six months that they've had them.

Topics

#configuration management#compliance drift#desktop hardening#configuration baseline

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice