350-201 Question 68
Select 3While working as a cybersecurity engineer for an organization, you are tasked with hardening a critical server to reduce its attack surface. Which of the following resources should you consult to ensure your hardening process aligns with industry standards and best practices?
- A
CIS (Center for Internet Security) Benchmarks
- B
NIST SP 800-53 Security and Privacy Controls
- C
Cisco Talos Threat Intelligence
- D
OWASP Top 10
- E
ISO/IEC 27001 Standard
Show answer and explanation
Correct answers: A, B, E
Explanation
Hardening a system involves implementing security measures to reduce its vulnerabilities. Industry standards and frameworks such as CIS Benchmarks, NIST SP 800-53, and ISO/IEC 27001 provide specific guidelines and best practices for securing systems. While Cisco Talos and OWASP are valuable cybersecurity resources, they do not focus on system hardening standards.
- A. Correct.
CIS Benchmarks provide comprehensive, vendor-neutral hardening guidelines for various systems and platforms, making them a key resource for system hardening.
- B. Correct.
NIST SP 800-53 outlines security and privacy controls that can be applied to federal information systems and organizations, offering a robust framework for system hardening.
- C. Incorrect.
Cisco Talos Threat Intelligence focuses on threat research and detection, which is useful for identifying threats but does not provide specific hardening guidelines.
- D. Incorrect.
OWASP Top 10 is a list of common web application vulnerabilities and does not directly address system hardening requirements.
- E. Correct.
ISO/IEC 27001 provides an international standard for information security management systems and includes guidelines that can be used for system hardening.