nerdexam
(ISC)2(ISC)2

CISSP · Question #1486

CISSP Question #1486: Real Exam Question with Answer & Explanation

The correct answer is C: Operating System (OS) baselines. Operating System (OS) baselines are of greatest assistance to auditors when reviewing system configurations. OS baselines are standard or reference configurations that define the desired and secure state of an OS, including the settings, parameters, patches, and updates. OS basel

Submitted by sofia.br· Mar 5, 2026Security Assessment and Testing

Question

Which of the following is of GREATEST assistance to auditors when reviewing system configurations?

Options

  • AChange management processes
  • BUser administration procedures
  • COperating System (OS) baselines
  • DSystem backup documentation

Explanation

Operating System (OS) baselines are of greatest assistance to auditors when reviewing system configurations. OS baselines are standard or reference configurations that define the desired and secure state of an OS, including the settings, parameters, patches, and updates. OS baselines can provide several benefits, such as: Improving the security and compliance of the OS by applying the best practices and recommendations from the vendors, authorities, or frameworks Enhancing the performance and efficiency of the OS by optimizing the resources and functions Increasing the consistency and uniformity of the OS by reducing the variations and deviations Facilitating the monitoring and auditing of the OS by providing a baseline for comparison and OS baselines are of greatest assistance to auditors when reviewing system configurations, because they can enable the auditors to evaluate and verify the current and actual state of the OS against the desired and secure state of the OS. OS baselines can also help the auditors to identify and report any gaps, issues, or risks in the OS configurations, and to recommend or implement any corrective or preventive actions.

Topics

#System hardening#Security baselines#Configuration management#Auditing

Community Discussion

No community discussion yet for this question.

Full CISSP PracticeBrowse All CISSP Questions