CCCS-203B · Question #52
A security administrator is reviewing their cloud environment's configurations to ensure compliance with the CIS (Center for Internet Security) Benchmarks. Which of the following actions is most…
The correct answer is A. Run an automated compliance assessment tool that supports CIS Benchmarks. Option A: This is the correct answer because automated tools are specifically designed to assess cloud configurations against CIS Benchmarks, providing actionable insights into compliance gaps. These tools are regularly updated to reflect the latest industry benchmarks and…
Question
A security administrator is reviewing their cloud environment's configurations to ensure compliance with the CIS (Center for Internet Security) Benchmarks. Which of the following actions is most appropriate for identifying compliance gaps with CIS Benchmarks?
Options
- ARun an automated compliance assessment tool that supports CIS Benchmarks.
- BEnable all permissions in the cloud environment to minimize risk.
- CDisable logging and monitoring to avoid compliance violations.
- DUse manual auditing techniques to compare configurations against CIS documentation.
How the community answered
(33 responses)- A91% (30)
- B6% (2)
- D3% (1)
Explanation
Option A: This is the correct answer because automated tools are specifically designed to assess cloud configurations against CIS Benchmarks, providing actionable insights into compliance gaps. These tools are regularly updated to reflect the latest industry benchmarks and significantly reduce human error compared to manual methods. Option B: This is incorrect because enabling all permissions creates significant security risks, such as privilege escalation and unauthorized access, and violates the principle of least privilege. It directly contradicts compliance requirements. Option C: This is incorrect because logging and monitoring are often mandatory components of compliance frameworks like CIS. Disabling them would lead to non-compliance and hinder incident response efforts. Option D: While manual auditing can be effective, it is time-consuming, prone to human error, and not scalable for dynamic cloud environments. It is better suited as a secondary measure rather than the primary approach.
Topics
Community Discussion
No community discussion yet for this question.