nerdexam
Isaca

CISM · Question #44

What is the PRIMARY objective of implementing standard security configurations?

The correct answer is D. Control vulnerabilities and reduce threats from changed configurations. The primary objective of implementing standard security configurations is to control vulnerabilities and mitigate threats arising from inconsistent or insecure system settings.

Submitted by hassan_iq· Apr 18, 2026Information Security Program Development and Management

Question

What is the PRIMARY objective of implementing standard security configurations?

Options

  • AMaintain a flexible approach to mitigate potential risk to unsupported systems.
  • BMinimize the operational burden of managing and monitoring unsupported systems.
  • CCompare configurations between supported and unsupported systems.
  • DControl vulnerabilities and reduce threats from changed configurations.

How the community answered

(21 responses)
  • A
    5% (1)
  • C
    5% (1)
  • D
    90% (19)

Why each option

The primary objective of implementing standard security configurations is to control vulnerabilities and mitigate threats arising from inconsistent or insecure system settings.

AMaintain a flexible approach to mitigate potential risk to unsupported systems.

Standard configurations promote consistency and reduce flexibility, especially for unsupported systems where deviations increase risk, rather than maintaining a flexible approach.

BMinimize the operational burden of managing and monitoring unsupported systems.

While standardization can streamline management, its primary security objective is not to minimize the operational burden of unsupported systems but rather to secure them.

CCompare configurations between supported and unsupported systems.

Comparing configurations is a task performed with standards, but the core objective of implementing them is to reduce risks from insecure settings, not merely for comparison.

DControl vulnerabilities and reduce threats from changed configurations.Correct

Standard security configurations, often referred to as security baselines, establish a secure and consistent state for systems and applications. This standardization significantly reduces the attack surface by minimizing misconfigurations and known vulnerabilities, thereby controlling threats and strengthening the overall security posture.

Concept tested: Security baselines and configuration management

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-baselines/security-baselines-overview

Topics

#Configuration Management#Security Baselines#Vulnerability Management#Threat Reduction

Community Discussion

No community discussion yet for this question.

Full CISM Practice