350-201 Question 67
Select 3An enterprise security team is tasked with hardening their systems to meet industry standards and best practices. Which of the following resources should they consult to ensure compliance with widely recognized security benchmarks?
- A
Center for Internet Security (CIS) Benchmarks
- B
National Institute of Standards and Technology (NIST) Special Publications
- C
Cisco Talos Intelligence Group
- D
Open Web Application Security Project (OWASP) Guidelines
- E
ISO/IEC 27001 Standard
Show answer and explanation
Correct answers: A, B, E
Explanation
To determine resources for system hardening, organizations should rely on established and widely recognized standards and guidelines. CIS Benchmarks, NIST Special Publications, and ISO/IEC 27001 are authoritative sources for system hardening recommendations. While other resources like Cisco Talos and OWASP are valuable for specific areas of cybersecurity, they do not focus on general system hardening benchmarks.
- A. Correct.
The Center for Internet Security (CIS) provides detailed benchmarks for hardening systems and ensuring compliance with industry standards. These benchmarks are widely used as a foundation for securing systems.
- B. Correct.
NIST Special Publications, such as the NIST 800 series, offer comprehensive guidance on securing systems and implementing cybersecurity best practices. They are a key resource for aligning with industry standards.
- C. Incorrect.
Cisco Talos Intelligence Group is a valuable resource for threat intelligence and malware analysis but does not provide specific hardening standards or benchmarks for systems.
- D. Incorrect.
The OWASP Guidelines are primarily focused on web application security rather than general system hardening, making them less relevant to this context.
- E. Correct.
ISO/IEC 27001 is an international standard for information security management systems (ISMS) and provides a framework for securing systems, making it a critical resource for hardening efforts.