SY0-701 exam dumps

SY0-701 practice question 252 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 252

Single answerSecure baselines: Establish , Deploy , Maintain

A security administrator is standardizing 500 newly issued Windows laptops for a hybrid workforce. The company must reduce configuration drift, ensure systems are hardened before users receive them, and keep the approved settings consistent over time as business requirements change. Which approach BEST addresses the full lifecycle of secure baselines?

  1. A

    Create a hardened baseline from an industry benchmark, deploy it through centralized configuration management to all laptops, and use continuous compliance monitoring with change control to maintain it

  2. B

    Install endpoint protection on each laptop, allow users local administrator rights for flexibility, and review security settings annually

  3. C

    Build one gold image for initial deployment, then let support technicians make local configuration changes as needed without updating the standard

  4. D

    Rely on monthly vulnerability scans to identify weak settings and manually remediate systems that fail the scan

Show answer and explanation

Correct answer: A

Explanation

Secure baseline management is a lifecycle process: establish a standard, deploy it consistently, and maintain it as systems and requirements change. Best practice is to begin with a recognized hardening source, such as CIS Benchmarks, NIST guidance, or vendor security baselines, then tailor the settings to business needs. Deployment should be automated and centralized using tools such as Group Policy, Microsoft Intune, mobile device management platforms, or enterprise configuration management systems. Maintenance requires continuous assessment for drift, periodic review, version control, and change management so the baseline remains effective and supportable. This approach aligns with common guidance from NIST SP 800-123 for general server and system security, NIST SP 800-128 for security-focused configuration management, and the CIS Controls emphasis on secure configuration of enterprise assets and software.

  • A. Correct.

    Correct. This option covers all three baseline phases: establish, deploy, and maintain. Establishing the baseline from a recognized benchmark such as CIS Benchmarks or vendor security baselines provides a vetted starting point. Deploying through centralized configuration management, such as Group Policy, MDM, or other endpoint management tools, ensures consistency at scale. Maintaining the baseline through continuous compliance monitoring, configuration auditing, and formal change control reduces configuration drift while allowing approved updates as requirements evolve. This is the most complete and operationally sound approach.

  • B. Incorrect.

    Incorrect. Endpoint protection is important, but it is not a substitute for a secure configuration baseline. Granting users local administrator rights typically increases risk and undermines baseline integrity because users can alter security settings and install unauthorized software. Reviewing settings only annually is too infrequent to effectively maintain a secure baseline in a changing environment.

  • C. Incorrect.

    Incorrect. A gold image can help with initial deployment, but by itself it does not maintain a baseline over time. Allowing technicians to make ad hoc local changes without updating the approved standard creates configuration drift and inconsistency. This weakens security and makes future troubleshooting, auditing, and compliance efforts more difficult.

  • D. Incorrect.

    Incorrect. Vulnerability scans are useful for detecting issues, but they are primarily a detective control rather than a complete baseline management strategy. Manually remediating systems after scans is reactive, labor-intensive, and less effective than centrally enforcing approved configurations. This option also does not adequately address formal establishment and controlled maintenance of the baseline.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam