A Linux administrator is responsible for deploying a new set of web servers. According to company policy, all new systems must be hardened using a globally recognized, consensus-driven standard that provides prescriptive configuration baselines. The administrator must be able to prove compliance with this standard for future audits. Which of the following should the administrator implement to meet this requirement?
The correct answer is CIS Benchmarks. The Center for Internet Security (CIS) Benchmarks are globally recognized, consensus-driven best practices for securely configuring IT systems, software, networks, and cloud infrastructure. They provide prescriptive, step-by-step guidance for system hardening that is accepted by governments, businesses, and academic institutions. Adhering to CIS Benchmarks helps organizations meet compliance requirements for frameworks like PCI DSS, HIPAA, and NIST.
OpenSCAP is a tool used to automate the process of auditing, vulnerability scanning, and checking for compliance against security policies like the CIS Benchmarks, but it is not the benchmark or standard itself.
The /etc/sudoers file is a critical configuration file for managing user privileges via sudo, but it only represents a small part of a comprehensive system hardening strategy.
AIDE is a file integrity checker used to detect unauthorized modifications to system files, which is a component of security auditing, but it does not provide prescriptive configuration baselines for system hardening.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are CIS Benchmarks used for?
Open an interactive chat with Bash
How is OpenSCAP related to CIS Benchmarks?
Open an interactive chat with Bash
Why is `/etc/sudoers` not sufficient for system hardening?
Open an interactive chat with Bash
CompTIA Linux+ XK0-006 (V8)
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .