ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
An organization is deploying new servers to support a critical business application. Before the servers are put into production, the IT team ensures that each server is configured according to a predefined hardening guide, which includes disabling unnecessary services, closing unused ports, and setting strong password policies for local accounts. This practice is an example of:
- AConfiguration management
- BVulnerability scanning
- CPatch management
- DChange management
Show answer & explanationAnswer & explanation
Correct answer: A. Configuration management
The scenario describes ensuring systems adhere to a predefined security baseline (hardening guide) by setting specific configurations like disabling services and closing ports. This is a core activity of configuration management.
Why the other options are wrong
- B. Vulnerability scanning identifies weaknesses, but the scenario describes the *process* of setting up security configurations.
- C. Patch management is about applying updates, not initial system hardening or ongoing configuration consistency.
- D. Change management is the process for controlling *any* modification, but configuration management specifically deals with maintaining desired system states.
Configuration Management
The process of maintaining a consistent and secure state of IT systems and software throughout their lifecycle, often by adhering to predefined baselines and policies.
- Ensures systems meet security baselines
- Prevents configuration drift
- Supports compliance and audit readiness
Memory trick: Configuring systems correctly keeps them secure and stable.