Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A security auditor is checking an organization's workstations and discovers that several critical security settings, such as password complexity and automatic screen locking, are inconsistent across different departments. The organization wants to ensure a uniform and hardened security posture for all endpoints. Which endpoint security concept should they implement to address this inconsistency?
- APatch Management
- BSecure Configuration Baseline
- CVulnerability Scanning
- DApplication Whitelisting
Show answer & explanationAnswer & explanation
Correct answer: B. Secure Configuration Baseline
A secure configuration baseline defines a set of standardized, hardened security settings for systems and applications. Implementing and enforcing such a baseline ensures consistency and a strong security posture across all endpoints.
Why the other options are wrong
- A. Patch management focuses on applying software updates, not standardizing security settings.
- C. Vulnerability scanning identifies weaknesses but doesn't define or enforce consistent configurations.
- D. Application whitelisting controls which applications can run, not general system security settings.
Secure Configuration Baseline
A standardized set of security configurations that defines the minimum security requirements for systems, applications, and network devices within an organization.
- Ensures consistent security posture.
- Reduces misconfigurations and attack surface.
- Often based on industry standards (e.g., CIS Benchmarks).
Memory trick: Baseline: Everyone builds on the same strong foundation.