Which of the following would be the BEST source of reference during the revision process?

A Chief Information Security Officer (CISO is reviewing and revising system configuration and hardening guides that were developed internally and have been used several years to secure the organization’s systems. The CISO knows improvements can be made to the guides.
Which of the following would be the BEST source of reference during the revision process?
A. CVE database
B. Internal security assessment reports
C. Industry-accepted standards
D. External vulnerability scan reports
E. Vendor-specific implementation guides

How to PASS CAS-004 in First Attempt?

FULL Printable PDF and Software. VALID exam to help you PASS.

comptia-exams

8 thoughts on “Which of the following would be the BEST source of reference during the revision process?

  1. All of the answers can be used to guide configuration/hardening guides, but the CVE database is the industry standard reference for vulnerability enumeration.

    I would go with A

  2. The CISO knows improvements can be ‘made’ to the guides.
    NIST + ISO

    so C is correct

  3. @ The real 007, I think you would perform a security assessment based on the exact internal security assessment; how else would you know if there are areas that need improvement. Yeah, vendor specific guides help determine if you are meeting their implementations, but they are just that…guides. Thoughts?

  4. The answer is D.

    If you were to improve your security posture, you would not perform a security assessment based on the exact internal security assessment you are trying to improve. It would be a biased assessment if done internally.

    To view what your security posture looks like, a third party external vulnerability assessment will be required. This will tell you everything you need to know if your system requires update to a hardened computer.

  5. Not A, makes no sense.
    A. No, will tell you vulnerabilities for products, don’t see how this would be correct.
    B. Yes would tell current posture and areas of improvement.
    C. No this is more like USB standards and the like.
    D. No, only covers external and question specifically says internal (sort of)
    E. No, these should have been configured in the baseline.

    So answer is B.

    4
    1

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.