lab 18 Flashcards
Which of the following are headings or section titles in the security policy document from the SANS organization? (Select all that apply)
Overview
Purpose
Scope
Policy
Policy Compliance
Revision History
Redactions
Overview
Purpose
Scope
Policy
Policy Compliance
Revision History
The Server Security Policy references two other policies related to this policy document’s concepts. What are those two other policies?
Audit Policy
DMZ Equipment Policy
Software Installation Policy
Password Protection Policy
Wireless Communication Policy
Audit Policy
DMZ Equipment Policy
The Microsoft Windows Server benchmarks are available for a wide range of versions of this OS. Which of the following are included on the list at CIS?
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2016
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2016
CIS Benchmarks are available for which of the following products?
Amazon Web Services
Apple iOS
Docker
NGINX
pfSense Firewall
Zoom
Amazon Web Services
Apple iOS
Docker
NGINX
pfSense Firewall
Zoom
Which of the following is not a Category of Security Policy Templates from the SANS website?
Retired
Incident Handling
Application Security
IoT and ICS Security
IoT and ICS Security
Which of the following is a category of Benchmark from CIS?
DevSecOps Tools
IoT devices
Edge computing
Imbedded systems
Static OS solutions
DevSecOps Tools
Once a security template, baseline, or benchmark has been obtained from a third-party, what tasks are your responsibility? (Select two)
Public dissemination
Scoping to your business objectives
Tailoring to your system functions
Providing support documentation
Scoping to your business objectives
Tailoring to your system functions
Network security baselines describe a set of minimum security controls and configurations for a network. They provide a starting point for the hardening process.
True
False
True
Center for Internet Security (CIS) Benchmarks can be applied directly to production systems for optimal security compliance.
False
True
False