nerdexam
CompTIA

CS0-003 · Question #253

An organization would like to ensure its cloud infrastructure has a hardened configuration. A requirement is to create a server image that can be deployed with a secure template. Which of the followin

The correct answer is A. CIS Benchmarks. CIS Benchmarks for Hardened Server Images CIS (Center for Internet Security) Benchmarks are the best resource here because they provide specific, prescriptive technical guidelines for securely configuring operating systems, cloud platforms, and server images - directly supporting

Submitted by anna_se· Mar 6, 2026Vulnerability Management

Question

An organization would like to ensure its cloud infrastructure has a hardened configuration. A requirement is to create a server image that can be deployed with a secure template. Which of the following is the best resource to ensure secure configuration?

Options

  • ACIS Benchmarks
  • BPCI DSS
  • COWASP Top Ten
  • DISO 27001

How the community answered

(23 responses)
  • A
    91% (21)
  • B
    4% (1)
  • D
    4% (1)

Explanation

CIS Benchmarks for Hardened Server Images

CIS (Center for Internet Security) Benchmarks are the best resource here because they provide specific, prescriptive technical guidelines for securely configuring operating systems, cloud platforms, and server images - directly supporting the creation of hardened, deployable templates. CIS even offers pre-built CIS Hardened Images that can be deployed directly in cloud environments like AWS, Azure, and GCP.

Why the distractors are wrong:

  • PCI DSS is a compliance framework specifically for protecting payment card data - not a technical configuration guide for general server hardening
  • OWASP Top Ten focuses on web application security vulnerabilities, not server/infrastructure configuration
  • ISO 27001 is a broad information security management standard for organizational policies and controls, not a technical hardening guide

Memory Tip: Think of CIS Benchmarks as a "recipe book" for building secure systems - they give you step-by-step technical instructions. The other options are more like business policies or risk frameworks that tell you what to achieve, while CIS tells you exactly how to configure it. If the question mentions hardening, configuration baselines, or secure images, CIS Benchmarks is almost always the answer.

Topics

#Cloud Security#Security Hardening#Configuration Management#Security Standards

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice