PSE-STRATA · Question #209
Which task would be included in the Best Practice Assessment (BPA) tool?
The correct answer is B. Identify and provide recommendations for device configurations. Option B is correct because the Best Practice Assessment (BPA) tool is specifically designed to evaluate security device configurations - such as firewalls - against vendor-recommended best practices, then surface actionable recommendations to improve security posture. Its core…
Question
Which task would be included in the Best Practice Assessment (BPA) tool?
Options
- AIdentify sanctioned and unsanctioned software-as-a-service (SaaS) applications.
- BIdentify and provide recommendations for device configurations.
- CIdentify the threats associated with each application.
- DIdentify the visibility and presence of command-and-control (C2) sessions.
How the community answered
(43 responses)- A14% (6)
- B79% (34)
- C2% (1)
- D5% (2)
Explanation
Option B is correct because the Best Practice Assessment (BPA) tool is specifically designed to evaluate security device configurations - such as firewalls - against vendor-recommended best practices, then surface actionable recommendations to improve security posture. Its core function is configuration analysis, not traffic inspection or threat detection.
Why the distractors are wrong:
- A (Sanctioned/unsanctioned SaaS apps) describes a Cloud Access Security Broker (CASB) or SaaS Security Posture Management function, not a device configuration tool.
- C (Threats associated with each application) aligns with App-ID threat intelligence or Threat Prevention features, which map application behavior to known risks - a separate capability from configuration assessment.
- D (C2 session visibility) is a threat detection/hunting task handled by tools like a SIEM, EDR, or dedicated C2 detection capabilities, not a best-practice configuration reviewer.
Memory tip: Think of BPA as a "configuration report card" - it grades how well your device is set up, not what traffic is flowing through it. If the answer involves analyzing packets, traffic, or live threats, it's the wrong category for BPA.
Community Discussion
No community discussion yet for this question.