ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

An organization is deploying new servers to support a critical business application. Before the servers are put into production, the IT team ensures that each server is configured according to a predefined hardening guide, which includes disabling unnecessary services, closing unused ports, and setting strong password policies for local accounts. This practice is an example of:

  1. AConfiguration management
  2. BVulnerability scanning
  3. CPatch management
  4. DChange management
Show answer & explanation

Correct answer: A. Configuration management

The scenario describes ensuring systems adhere to a predefined security baseline (hardening guide) by setting specific configurations like disabling services and closing ports. This is a core activity of configuration management.

Why the other options are wrong

  • B. Vulnerability scanning identifies weaknesses, but the scenario describes the *process* of setting up security configurations.
  • C. Patch management is about applying updates, not initial system hardening or ongoing configuration consistency.
  • D. Change management is the process for controlling *any* modification, but configuration management specifically deals with maintaining desired system states.

Configuration Management

The process of maintaining a consistent and secure state of IT systems and software throughout their lifecycle, often by adhering to predefined baselines and policies.

  • Ensures systems meet security baselines
  • Prevents configuration drift
  • Supports compliance and audit readiness

Memory trick: Configuring systems correctly keeps them secure and stable.

More Security Operations questions