Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A large enterprise is struggling to maintain consistent security configurations across its thousands of endpoints, including desktops, laptops, and servers. New devices are often deployed with default settings, and existing devices frequently drift from the hardened baseline. Which endpoint security best practice, when properly implemented, would directly address these challenges by defining and enforcing a standardized, secure state for all endpoints?
- ASecure Configuration Baseline
- BPatch Management
- CIncident Response Plan
- DUser Awareness Training
Show answer & explanationAnswer & explanation
Correct answer: A. Secure Configuration Baseline
A Secure Configuration Baseline defines a standardized set of security settings and configurations that all endpoints must adhere to. Implementing and enforcing such a baseline using configuration management tools helps prevent configuration drift and ensures consistent security across the enterprise.
Why the other options are wrong
- B. Patch Management updates software, it doesn't define or enforce overall security settings.
- C. An Incident Response Plan deals with security incidents after they occur, not proactive configuration enforcement.
- D. User Awareness Training educates users, but doesn't technically enforce endpoint configurations.
Secure Configuration Baseline
A documented set of security settings and configurations that define the minimum acceptable security posture for an information system or component, used to ensure consistency and reduce vulnerabilities across an organization's endpoints.
- Standardizes security settings across all similar systems.
- Helps prevent configuration drift and reduces attack surface.
- Often based on industry standards (e.g., CIS Benchmarks, NIST guides).
Memory trick: A baseline is like a blueprint for a secure house – every part must match the plan.