CCSP · Question #853
The baseline should cover which of the following?
The correct answer is C. As many systems throughout the organization as possible. A security baseline defines the minimum acceptable security configuration for systems in an organization. To be effective, it must be applied as broadly as possible across all systems - not limited to specific data types (A), not restricted to only regulated systems (B), and…
Question
The baseline should cover which of the following?
Options
- AData breach alerting and reporting
- BAll regulatory compliance requirements
- CAs many systems throughout the organization as possible
- DA process for version control
How the community answered
(25 responses)- A8% (2)
- C88% (22)
- D4% (1)
Explanation
A security baseline defines the minimum acceptable security configuration for systems in an organization. To be effective, it must be applied as broadly as possible across all systems - not limited to specific data types (A), not restricted to only regulated systems (B), and not focused solely on process controls like version control (D). The goal of a baseline is uniform, consistent hardening across the entire environment. Narrow baselines leave gaps that attackers can exploit on uncovered systems.
Topics
Community Discussion
No community discussion yet for this question.