350-201 Question 65
Select 3You are tasked with hardening an organization's systems to align with industry standards. Which resources would be the most appropriate to reference for guidance on system hardening practices?
- A
The Center for Internet Security (CIS) Benchmarks
- B
The National Institute of Standards and Technology (NIST) Special Publications
- C
Vendor-specific system hardening guides
- D
The Payment Card Industry Data Security Standard (PCI DSS)
- E
The Open Web Application Security Project (OWASP) Top Ten
Show answer and explanation
Correct answers: A, B, C
Explanation
System hardening involves securing systems against potential vulnerabilities by following established guidelines and best practices. Resources like the CIS Benchmarks, NIST Special Publications, and vendor-specific hardening guides provide detailed and authoritative recommendations for securing systems, making them the most appropriate references for hardening efforts. While PCI DSS and OWASP Top Ten focus on specific security domains, they do not provide comprehensive guidance for system hardening.
- A. Correct.
The Center for Internet Security (CIS) Benchmarks are widely recognized as authoritative resources for system hardening, providing practical and specific recommendations for securing various platforms.
- B. Correct.
The National Institute of Standards and Technology (NIST) Special Publications, such as SP 800-53, provide comprehensive guidelines for system security and hardening, particularly for federal systems but applicable to other organizations as well.
- C. Correct.
Vendor-specific system hardening guides provide tailored recommendations for securing products and systems from particular vendors, making them highly relevant for system-specific hardening efforts.
- D. Incorrect.
The Payment Card Industry Data Security Standard (PCI DSS) is a compliance framework focused on securing payment card data and does not comprehensively address system hardening for all types of systems.
- E. Incorrect.
The Open Web Application Security Project (OWASP) Top Ten addresses web application vulnerabilities rather than general system hardening practices, so it is not the best resource for this task.