nerdexam
CompTIA

CV0-003 · Question #857

An organization's executives would like to allow access to devices that meet the corporate security compliance levels. Which of the following criteria are most important for the organization to consid

The correct answer is B. Firmware D. OS patch level. Firmware version and OS patch level are the most critical compliance criteria because they directly reflect whether a device's foundational software layers are free from known, exploitable vulnerabilities.

Security

Question

An organization's executives would like to allow access to devices that meet the corporate security compliance levels. Which of the following criteria are most important for the organization to consider? (Choose two.)

Options

  • ASerial number
  • BFirmware
  • CAntivirus version and definition
  • DOS patch level
  • ECPU architecture
  • FManufacturer

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    89% (32)
  • C
    3% (1)
  • F
    6% (2)

Why each option

Firmware version and OS patch level are the most critical compliance criteria because they directly reflect whether a device's foundational software layers are free from known, exploitable vulnerabilities.

ASerial number

A serial number is a unique hardware identifier used for asset tracking, not for assessing the security or compliance state of a device.

BFirmwareCorrect

Firmware is the low-level software embedded in hardware components; outdated firmware can contain unpatched vulnerabilities that expose the device at a layer below the OS, making it a key compliance checkpoint.

CAntivirus version and definition

Antivirus version and definition status is a useful secondary control but is less foundational than firmware and OS patch level, which address vulnerabilities at a lower and broader level.

DOS patch levelCorrect

The OS patch level directly indicates whether known CVEs and security vulnerabilities have been remediated on the device, which is the primary measure of a device's security posture in any compliance framework.

ECPU architecture

CPU architecture describes hardware design and has no direct bearing on whether a device meets security compliance requirements.

FManufacturer

The manufacturer of a device does not determine whether that specific device is patched, updated, or otherwise compliant with corporate security policies.

Concept tested: Device compliance posture assessment for network access control

Source: https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

Topics

#device compliance#endpoint security#OS patch level#firmware management

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice