exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 441 discussion

Actual exam question from CompTIA's SY0-601
Question #: 441
Topic #: 1
[All SY0-601 Questions]

An organization wants to quickly assess how effectively the IT team hardened new laptops. Which of the following would be the best solution to perform this assessment?

  • A. Install a SIEM tool and properly configure it to read the OS configuration files
  • B. Load current baselines into the existing vulnerability scanner
  • C. Maintain a risk register with each security control marked as compliant or non-compliant
  • D. Manually review the secure configuration guide checklists
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ApplebeesWaiter1122
Highly Voted 2 years, 1 month ago
Selected Answer: B
Loading current baselines into the existing vulnerability scanner can help organizations quickly assess the security posture of their IT systems, including new laptops. A baseline is a set of recommended security settings for a particular operating system or application, and loading these baselines into a vulnerability scanner can help identify any deviations from the recommended settings. Vulnerability scanners are automated tools that can be used to identify and report on security vulnerabilities in IT systems. By loading the current baselines into the vulnerability scanner, the scanner can compare the actual security settings of the new laptops against the recommended settings and flag any deviations as potential vulnerabilities. This approach is beneficial because it is automated and can quickly scan a large number of systems for vulnerabilities. Additionally, vulnerability scanners can be configured to run on a regular schedule, allowing organizations to continuously monitor their systems for new vulnerabilities and potential security threats.
upvoted 8 times
...
mawrong
Highly Voted 1 year, 11 months ago
Selected Answer: B
Both B and D are correct so you will have to use the process of elimination. "The keywords here are "'quickly access''. Manually reviewing the checklist will take a while. what if it's 1000 laptops? This is just a trick question typical to CompTIA.
upvoted 6 times
...
cyberPunk28
Most Recent 1 year, 6 months ago
Selected Answer: B
B. Load current baselines into the existing vulnerability scanner
upvoted 1 times
...
sujon_london
1 year, 9 months ago
Selected Answer: B
The scale of the assessment when dealing with may be multiple laptops. In the context of quickly assessing the security hardening of numerous laptops, manually reviewing secure configuration guide checklists may not be the most efficient or practical solution. Reviewing each laptop's configuration manually could be time-consuming and error-prone.In such a scenario, a combination of automated tools and processes would likely be more effective. Here's a modified approach:B. Load current baselines into the existing vulnerability scanner.By loading the current baselines into a vulnerability scanner, you can perform automated scans across multiple laptops simultaneously. This allows for a quicker assessment of security configurations and can identify common vulnerabilities or misconfigurations efficiently.
upvoted 1 times
...
ronah
2 years ago
Selected Answer: D
D. Manually review the secure configuration guide checklists. (this makes sense ) Manually reviewing the secure configuration guide checklists allows for a focused and detailed assessment of the specific security hardening measures implemented on the laptops. These checklists typically provide step-by-step instructions on how to configure the operating system and applications securely, ensuring that recommended security controls are in place. why i dont agree on B because of this reason per chat gpt Option B, loading current baselines into the existing vulnerability scanner, primarily focuses on identifying vulnerabilities in the system rather than assessing the effectiveness of the hardening measures. While vulnerability scanning is an important part of security assessments, it does not provide a comprehensive evaluation of the laptop's configuration hardening.
upvoted 1 times
Abdul2107
1 year, 9 months ago
The questions asks "quickly", that's why D. option, Manually, is wrong.
upvoted 3 times
...
...
fouserd
2 years, 1 month ago
Selected Answer: B
To quickly assess how effectively the IT team hardened new laptops, the organization could load current baselines into the existing vulnerability scanner. A vulnerability scanner is a tool that can automatically scan systems and devices for known vulnerabilities and misconfigurations. By loading current baselines into the scanner, the organization can quickly assess whether the new laptops meet the desired security standards.
upvoted 4 times
...
jskiff1
2 years, 1 month ago
The best solution to quickly assess how effectively the IT team hardened new laptops would be B. Load current baselines into the existing vulnerability scanner. This will allow the organization to quickly scan the laptops and compare their configurations against the current baselines to identify any deviations or vulnerabilities.
upvoted 1 times
...
mouettespaghetti
2 years, 1 month ago
-D D. Manually review the secure configuration guide checklists would be the best solution to quickly assess how effectively the IT team hardened new laptops. The other options may be useful for ongoing monitoring and assessment, but they would not be the most efficient or effective way to quickly assess the effectiveness of the IT team's hardening of new laptops.
upvoted 2 times
fouserd
2 years, 1 month ago
How can it possibly manually review the guide checklist? That wouldn't be quick. Please don't troll, some of us are here trying to do our best to study and pass the exam. This cost us money and time. JSKIFF1 is correct, the answer would be B.
upvoted 5 times
Dutch012
2 years, 1 month ago
He is donig his best to learn too, this is his opinion and this is why there is a discussion section in the first place
upvoted 4 times
...
ronah
2 years ago
the reason why its not bOption B, loading current baselines into the existing vulnerability scanner, primarily focuses on identifying vulnerabilities in the system rather than assessing the effectiveness of the hardening measures. While vulnerability scanning is an important part of security assessments, it does not provide a comprehensive evaluation of the laptop's configuration hardening.
upvoted 1 times
mawrong
1 year, 11 months ago
Most vulnerability scanners such as Nessus allow you to carry out configuration scans to check if endpoints meet your compliance standards. Read it here: https://docs.tenable.com/nessus/Content/ScanAndPolicyTemplates.htm
upvoted 1 times
...
...
ronah
2 years ago
The best solution to quickly assess how effectively the IT team has hardened new laptops would be: D. Manually review the secure configuration guide checklists. Manually reviewing the secure configuration guide checklists allows for a focused and detailed assessment of the specific security hardening measures implemented on the laptops. These checklists typically provide step-by-step instructions on how to configure the operating system and applications securely, ensuring that recommended security controls are in place. chatgpt
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...