nerdexam
(ISC)2

CCSP · Question #366

What is the best source for information about securing a physical asset's BIOS?

The correct answer is C. Vendor documentation. Vendor documentation is the most authoritative and accurate source for BIOS security guidance because BIOS firmware is hardware-specific - each manufacturer implements it differently with unique settings, menus, and security features (e.g., Secure Boot, BIOS passwords, TPM…

Submitted by salim_om· Apr 18, 2026Cloud Platform & Infrastructure Security

Question

What is the best source for information about securing a physical asset's BIOS?

Options

  • ASecurity policies
  • BManual pages
  • CVendor documentation
  • DRegulations

How the community answered

(38 responses)
  • A
    3% (1)
  • C
    92% (35)
  • D
    5% (2)

Explanation

Vendor documentation is the most authoritative and accurate source for BIOS security guidance because BIOS firmware is hardware-specific - each manufacturer implements it differently with unique settings, menus, and security features (e.g., Secure Boot, BIOS passwords, TPM configuration). The vendor knows their product best and provides model-specific instructions. Security policies (A) are organizational documents that state what should be done, not how to do it at the hardware level. Manual pages (B) are for software/OS commands. Regulations (D) define compliance requirements but do not provide technical implementation details for specific hardware.

Topics

#BIOS security#Hardware security#Vendor documentation#Security information sources

Community Discussion

No community discussion yet for this question.

Full CCSP Practice