nerdexam
(ISC)2

CCSP · Question #853

The baseline should cover which of the following?

The correct answer is C. As many systems throughout the organization as possible. A security baseline defines the minimum acceptable security configuration for systems in an organization. To be effective, it must be applied as broadly as possible across all systems - not limited to specific data types (A), not restricted to only regulated systems (B), and…

Submitted by zhang_li· Apr 18, 2026Cloud Platform & Infrastructure Security

Question

The baseline should cover which of the following?

Options

  • AData breach alerting and reporting
  • BAll regulatory compliance requirements
  • CAs many systems throughout the organization as possible
  • DA process for version control

How the community answered

(25 responses)
  • A
    8% (2)
  • C
    88% (22)
  • D
    4% (1)

Explanation

A security baseline defines the minimum acceptable security configuration for systems in an organization. To be effective, it must be applied as broadly as possible across all systems - not limited to specific data types (A), not restricted to only regulated systems (B), and not focused solely on process controls like version control (D). The goal of a baseline is uniform, consistent hardening across the entire environment. Narrow baselines leave gaps that attackers can exploit on uncovered systems.

Topics

#Security Baseline#Configuration Management#Security Scope#Organizational Security

Community Discussion

No community discussion yet for this question.

Full CCSP Practice