CV0-003 · Question #857
An organization's executives would like to allow access to devices that meet the corporate security compliance levels. Which of the following criteria are most important for the organization to consid
The correct answer is B. Firmware D. OS patch level. Firmware version and OS patch level are the most critical compliance criteria because they directly reflect whether a device's foundational software layers are free from known, exploitable vulnerabilities.
Question
An organization's executives would like to allow access to devices that meet the corporate security compliance levels. Which of the following criteria are most important for the organization to consider? (Choose two.)
Options
- ASerial number
- BFirmware
- CAntivirus version and definition
- DOS patch level
- ECPU architecture
- FManufacturer
How the community answered
(36 responses)- A3% (1)
- B89% (32)
- C3% (1)
- F6% (2)
Why each option
Firmware version and OS patch level are the most critical compliance criteria because they directly reflect whether a device's foundational software layers are free from known, exploitable vulnerabilities.
A serial number is a unique hardware identifier used for asset tracking, not for assessing the security or compliance state of a device.
Firmware is the low-level software embedded in hardware components; outdated firmware can contain unpatched vulnerabilities that expose the device at a layer below the OS, making it a key compliance checkpoint.
Antivirus version and definition status is a useful secondary control but is less foundational than firmware and OS patch level, which address vulnerabilities at a lower and broader level.
The OS patch level directly indicates whether known CVEs and security vulnerabilities have been remediated on the device, which is the primary measure of a device's security posture in any compliance framework.
CPU architecture describes hardware design and has no direct bearing on whether a device meets security compliance requirements.
The manufacturer of a device does not determine whether that specific device is patched, updated, or otherwise compliant with corporate security policies.
Concept tested: Device compliance posture assessment for network access control
Source: https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started
Topics
Community Discussion
No community discussion yet for this question.