nerdexam
Isaca

CRISC · Question #345

The BEST way for an organization to ensure that servers are compliant to security policy is to review:

The correct answer is B. configuration settings.. To ensure servers comply with security policy, reviewing their configuration settings is the best method as it directly verifies whether implemented controls match policy requirements.

Submitted by wei.xz· Apr 18, 2026Information Technology and Security

Question

The BEST way for an organization to ensure that servers are compliant to security policy is to review:

Options

  • Achange logs.
  • Bconfiguration settings.
  • Cserver access logs.
  • Danti-malware compliance.

How the community answered

(70 responses)
  • A
    11% (8)
  • B
    76% (53)
  • C
    4% (3)
  • D
    9% (6)

Why each option

To ensure servers comply with security policy, reviewing their configuration settings is the best method as it directly verifies whether implemented controls match policy requirements.

Achange logs.

Change logs record modifications but don't inherently confirm if the current state of configuration meets policy.

Bconfiguration settings.Correct

Security policies dictate specific configuration requirements for servers (e.g., password complexity, port closures, installed software). Directly reviewing and auditing these configuration settings against the defined policy is the most effective way to determine if a server is compliant with established security baselines and organizational standards.

Cserver access logs.

Server access logs show who accessed the server and when, which is important for auditing, but does not directly confirm overall security policy compliance of the server's setup.

Danti-malware compliance.

Anti-malware compliance focuses on one specific aspect of security, whereas overall server security policy compliance is much broader.

Concept tested: Server security policy compliance auditing

Topics

#Server Security#Configuration Management#Compliance Monitoring#Security Policies

Community Discussion

No community discussion yet for this question.

Full CRISC Practice