712-50 exam dumps

712-50 practice question 328 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 328

Single answerIdentify various OS vulnerabilities and attacks and develop a plan for hardening OS systems

A global manufacturing company is integrating several recently acquired business units into its enterprise network. During initial assessments, the security team finds that many Windows and Linux servers were built from inconsistent images, several still have unnecessary services enabled, local administrator/root access is broadly assigned, and patch levels vary widely. Two production outages in the last quarter were traced to unauthorized changes made directly on servers, and a recent ransomware attempt exploited an unpatched service on a legacy system. The CIO asks the CISO to approve an OS hardening strategy that reduces attack surface, improves resilience, and can be governed consistently across business units without creating excessive operational disruption. Which action should the CISO prioritize FIRST as the foundation of the hardening program?

  1. A

    Implement a secure baseline configuration standard for Windows and Linux systems, including service minimization, configuration management, patch governance, and privileged access restrictions, then enforce it through automated build and compliance processes

  2. B

    Purchase a new endpoint detection and response platform and deploy it broadly, because runtime detection will compensate for inconsistent operating system configurations

  3. C

    Require administrators to manually review each server quarterly and document any unnecessary services or insecure settings for local remediation

  4. D

    Isolate all legacy systems into separate network segments and defer operating system hardening until the migration program is complete

Show answer and explanation

Correct answer: A

Explanation

The best answer is to establish and enforce secure baseline configurations as the foundation of the OS hardening program. In a CCISO context, the key issue is not just technical remediation but governance at scale: the CISO must select an approach that is standardized, auditable, measurable, and sustainable across multiple business units. Hardening begins with reducing attack surface and configuration variability through approved secure builds and system baselines. These baselines should include removal of unnecessary services, timely patching, least privilege, secure account management, logging, host-based firewall settings, and change control enforcement. Automation through configuration management and continuous compliance validation is critical to prevent drift and reduce operational disruption.

This approach aligns with widely accepted best practices from sources such as the CIS Benchmarks, NIST SP 800-123 (Guide to General Server Security), NIST SP 800-40 (Enterprise Patch Management Planning), and NIST SP 800-53 security controls related to configuration management, least functionality, vulnerability management, and access control. In practice, organizations often combine secure baselines with exception management for legacy systems, segmentation for assets that cannot meet standards immediately, and detective controls such as EDR. However, the baseline must come first because it defines what 'hardened' means and enables enterprise-wide enforcement.

  • A. Correct.

    Correct. Establishing secure baseline configurations is the most effective first step because it creates a repeatable, governable foundation for OS hardening across heterogeneous environments. A baseline typically covers removal or disabling of unnecessary services and software, standard patching requirements, secure configuration settings, logging, host firewall settings, account and privilege restrictions, and approved administrative methods. Enforcing that baseline through automated image builds, configuration management, and continuous compliance checking reduces the likelihood of drift and unauthorized changes. This directly addresses the scenario's root problems: inconsistent images, excessive privileges, varying patch levels, and service exposure.

  • B. Incorrect.

    Incorrect. EDR is valuable for detection and response, but it does not replace hardening. Runtime detection can help identify malicious behavior, yet unpatched services, weak configurations, and excessive privileges still increase exploitability and business risk. Choosing tooling before establishing a secure configuration standard treats symptoms rather than the root cause. A mature program typically uses EDR as a complementary control after or alongside baseline hardening, not as the foundational first action.

  • C. Incorrect.

    Incorrect. Manual quarterly reviews are too slow, too inconsistent, and too dependent on individual administrator skill to serve as the foundation of an enterprise hardening strategy. In this scenario, the organization already suffers from inconsistent builds and unauthorized changes; a manual process will not adequately prevent drift or ensure standardization across acquired units. It may be useful as a temporary validation activity, but it is not the right first priority for scalable governance.

  • D. Incorrect.

    Incorrect. Network segmentation is an important compensating control, especially for legacy systems that cannot be patched quickly, but deferring hardening leaves the broader server fleet exposed. Segmentation reduces lateral movement and exposure, yet it does not solve inconsistent OS configurations, unnecessary services, weak privilege management, or patch governance gaps across the environment. It should be part of the overall strategy, particularly for high-risk legacy assets, but not the primary first step.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam