350-201 Question 66
Select 3A cybersecurity analyst is tasked with hardening a network's systems to align with industry standards and best practices. Which of the following resources can be used to gather recommendations for system hardening?
- A
National Institute of Standards and Technology (NIST) Special Publications
- B
The Center for Internet Security (CIS) Benchmarks
- C
The MITRE ATT&CK Framework
- D
Cisco SecureX Dashboard
- E
Open Web Application Security Project (OWASP) Guidelines
Show answer and explanation
Correct answers: A, B, E
Explanation
To harden systems according to industry standards, professionals should rely on well-established resources such as NIST Special Publications, CIS Benchmarks, and OWASP Guidelines. These resources provide practical recommendations and configurations to enhance cybersecurity. While frameworks like MITRE ATT&CK and tools like Cisco SecureX are valuable for other aspects of cybersecurity, they do not focus on system hardening.
- A. Correct.
NIST Special Publications, such as the NIST 800 series, provide detailed guidelines for system hardening and cybersecurity best practices, making it a critical resource.
- B. Correct.
The CIS Benchmarks are widely recognized as industry standards for hardening systems and provide specific configuration guidelines to enhance security.
- C. Incorrect.
The MITRE ATT&CK Framework is a knowledge base for understanding adversary tactics and techniques but does not provide system hardening recommendations.
- D. Incorrect.
Cisco SecureX Dashboard is a security management tool but does not directly provide resources for system hardening standards.
- E. Correct.
The OWASP Guidelines focus on web application security and include recommendations for securing systems, making it relevant for system hardening in specific contexts.