exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 51 discussion

Actual exam question from CompTIA's SY0-601
Question #: 51
Topic #: 1
[All SY0-601 Questions]

Which of the following organizations sets frameworks and controls for optimal security configuration on systems?

  • A. ISO
  • B. GDPR
  • C. PCI DSS
  • D. NIST
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tjank
Highly Voted 2 years, 9 months ago
Both ISO and NIST have Frameworks for standards. when searching parts of the question "sets frameworks and controls for optimal security configuration" only NIST came up specifically. I personally hate these type of questions as I would utilize both to build from.
upvoted 29 times
rodwave
2 years, 7 months ago
Agreed, not a huge fan of the question either. The question only mentions security where both ISO and NIST would cover but I would lean towards NIST as its specifically for improving cybersecurity.
upvoted 6 times
...
LeDarius3762
1 year, 11 months ago
I would choose NIST just because the questions is stating "frameworks" not "standards" (ISO is a standard) I know is weird, but CompTIA is equally weird with these vague questions
upvoted 11 times
...
...
varun0
Highly Voted 2 years, 10 months ago
Selected Answer: D
NIST I guess
upvoted 23 times
...
Teleco0997
Most Recent 1 year, 7 months ago
Selected Answer: D
besides the word framework and not standard to differentiate between NIST and ISO; when it comes to security configuration on systems specifically, NIST is often more directly associated with detailed guidelines and controls. NIST's Special Publication 800-53 (which is mentioned in the official study guide), for example, provides a comprehensive catalog of security controls for federal information systems and organizations. So, ISO addresses broader aspects of information security, but NIST is often considered more focused on providing detailed security configurations and controls
upvoted 3 times
...
Dogeo
1 year, 8 months ago
NIST is USA specific if the question dosen't specify how are we supposed to know guess?
upvoted 2 times
...
sujon_london
1 year, 11 months ago
Selected Answer: D
Once mentioned security that’s should be recon it’s NIST
upvoted 1 times
...
Protract8593
1 year, 11 months ago
Selected Answer: D
NIST (National Institute of Standards and Technology) is the organization that sets frameworks and controls for optimal security configuration on systems. NIST is a non-regulatory agency of the United States Department of Commerce and plays a significant role in developing standards and guidelines for various aspects of information security, including cybersecurity best practices and security configuration.
upvoted 6 times
...
Tiazzed
1 year, 11 months ago
I think ist nist
upvoted 1 times
...
Selected Answer: D
The organization that sets frameworks and controls for optimal security configuration on systems is NIST (National Institute of Standards and Technology). NIST provides guidelines, standards, and best practices for various aspects of cybersecurity, including security configuration management. Their publications, such as the NIST Special Publication 800-53, provide detailed controls and recommendations for securing information systems and protecting sensitive data. ISO (International Organization for Standardization) develops and publishes international standards for various industries, including cybersecurity, but it does not specifically focus on security configuration management.
upvoted 3 times
...
JAMBER
2 years, 1 month ago
Selected Answer: D
Very vague question for such broad reaching organizations. I went with D- NIST, but ISO seemed very likely as well.
upvoted 1 times
...
goodmate
2 years, 3 months ago
National versus international. Some frameworks are used within a single country (and referred to as national frameworks), while others are used internationally. As an example, NIST created the Cybersecurity Framework, which focuses on cybersecurity activities and risks within the United States. In contrast, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) create and publish international standards. For example, ISO/IEC 27002 provides a framework for IT security. Source: Darill Gibson, ComptiaSecurity+ SY0-501 Study Guide, page: 690
upvoted 3 times
...
Omi0204
2 years, 3 months ago
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/security-frameworks/ NIST answer would be D
upvoted 1 times
...
ronniehaang
2 years, 5 months ago
Selected Answer: D
D. NIST (National Institute of Standards and Technology) sets frameworks and controls for optimal security configuration on systems. NIST provides guidelines, standards, and best practices for information security, including the development of security configuration baselines for various technologies, such as operating systems and applications.
upvoted 3 times
...
DALLASCOWBOYS
2 years, 5 months ago
D. NIST ( National Institute of Standards and Technology) is the standard used by organizations to establish fundamental controls and processes needed for optimum cybersecurity
upvoted 2 times
...
i_m_Jatin
2 years, 5 months ago
National Institute of Standards and Technology
upvoted 1 times
...
[Removed]
2 years, 5 months ago
Selected Answer: D
https://sopa.tulane.edu/blog/NIST-cybersecurity-framework#:~:text=The%20National%20Institute%20of%20Standards,and%20how%20it%20is%20implemented.
upvoted 1 times
...
shitgod
2 years, 6 months ago
The quality of this question is quite low...
upvoted 9 times
...
Knowledge33
2 years, 8 months ago
Selected Answer: D
ISO is for all standards, not only security, whereas NIST is only related to security.
upvoted 5 times
housecoatjapan
2 years, 3 months ago
Not true, but just memorize it. The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into physical science laboratory programs that include nanoscale science and technology, engineering, information technology, neutron research, material measurement, and physical measurement. From 1901 to 1988, the agency was named the National Bureau of Standards.[4]
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...