CRISC · Question #345
The BEST way for an organization to ensure that servers are compliant to security policy is to review:
The correct answer is B. configuration settings.. To ensure servers comply with security policy, reviewing their configuration settings is the best method as it directly verifies whether implemented controls match policy requirements.
Question
The BEST way for an organization to ensure that servers are compliant to security policy is to review:
Options
- Achange logs.
- Bconfiguration settings.
- Cserver access logs.
- Danti-malware compliance.
How the community answered
(70 responses)- A11% (8)
- B76% (53)
- C4% (3)
- D9% (6)
Why each option
To ensure servers comply with security policy, reviewing their configuration settings is the best method as it directly verifies whether implemented controls match policy requirements.
Change logs record modifications but don't inherently confirm if the current state of configuration meets policy.
Security policies dictate specific configuration requirements for servers (e.g., password complexity, port closures, installed software). Directly reviewing and auditing these configuration settings against the defined policy is the most effective way to determine if a server is compliant with established security baselines and organizational standards.
Server access logs show who accessed the server and when, which is important for auditing, but does not directly confirm overall security policy compliance of the server's setup.
Anti-malware compliance focuses on one specific aspect of security, whereas overall server security policy compliance is much broader.
Concept tested: Server security policy compliance auditing
Topics
Community Discussion
No community discussion yet for this question.