/
Enterprise Infrastructure Security Baselines
Save to my account
Sign up
Enterprise Infrastructure Security Baselines
Enterprise Infrastructure Security Baselines
Study
1
Question
What is a secure baseline for enterprise infrastructure?
Page 3
Answer
A secure baseline is a collection of standard configurations and settings for operating systems, network devices, software, cloud instances, patching and updates, access controls, logging, monitoring, password policies, encryption, endpoint protection, and other security controls.
2
Question
Why are secure baselines used in enterprise environments?
Page 3
Answer
They establish consistent security configurations across systems and devices. Consistency makes it possible to compare implementations against an accepted standard and identify deviations.
3
Question
How does configuration management support secure baselines?
Page 4
Answer
Configuration management helps organizations manage, deploy, and measure compliance with established secure baselines.
4
Question
Which configuration-management tools are listed for deploying secure settings?
Page 4
Answer
The listed tools are Puppet, Chef, and Ansible. Memory hook: imagine a puppet chef using an answer book to configure every machine.
5
Question
What does the Security Content Automation Protocol support?
Page 4
Answer
The Security Content Automation Protocol (SCAP) supports security-configuration assessment and compliance checking through tools such as OpenSCAP, CIS-CAT Pro, and SCAP Compliance Checker (SCC).
6
Question
Which tools are listed as SCAP-related compliance checkers?
Page 4
Answer
The listed tools are OpenSCAP, CIS-CAT Pro, and SCAP Compliance Checker (SCC). Memory hook: picture an open scanner, a CIS cat, and a compliance checker inspecting machines.
7
Question
Which organizations or sources provide secure configuration guidance?
Page 3
Answer
The listed sources are the Center for Internet Security (CIS), Security Technical Implementation Guides (STIGs), and vendor-provided guidance.
8
Question
Why should default credentials be changed on network devices?
Page 5
Answer
Changing default credentials is a security improvement for switches, routers, servers, and operating systems because it replaces initially supplied access information with organization-controlled credentials.
9
Question
How does disabling unnecessary functionality improve device security?
Page 6
Answer
Disabling unnecessary features on switches, routers, servers, and operating systems reduces the active functionality that must be secured. The listed examples include unnecessary services on servers and operating systems.
10
Question
Which management-protocol change improves switch and router security?
Page 5
Answer
Using secure management protocols improves the security of switches and routers.
11
Question
How do access control lists secure switches and routers?
Page 14
Answer
Access control lists (ACLs) control traffic at a network interface level by applying a list of permissions associated with a network device such as a router or switch.
12
Question
Why are logging and monitoring enabled on infrastructure devices?
Page 5
Answer
Logging and monitoring are listed as security improvements for switches, routers, servers, and operating systems. They provide visibility into device and system activity.
13
Question
How does port security contribute to switch protection?
Page 5
Answer
Port security is a listed change designed to improve the security of switches and routers by controlling or securing network-port access.
14
Question
Why should network equipment be physically secured?
Page 6
Answer
Physical security protects switches, routers, servers, equipment racks, server rooms, and datacenters from unauthorized physical access or interference.
15
Question
How does the least privilege principle secure servers?
Page 6
Answer
The least privilege principle is a listed server and operating-system security improvement. It limits access privileges to what is necessary for authorized activity.
16
Question
Why should software security patches and updates be applied regularly?
Page 6
Answer
Regularly applying software security patches and updates is a listed method for improving server and operating-system security. It keeps software updated as part of secure maintenance.
17
Question
Which additional protections are listed for server hardware and operating systems?
Page 6
Answer
The listed protections include firewalls, intrusion detection systems (IDS), strong access controls, antivirus and antimalware solutions, secure CIS or STIG configurations, logging and monitoring, and physical security.
18
Question
How do CIS and STIG baselines apply to server security?
Page 6
Answer
Servers and operating systems can use secure configurations based on CIS or STIG baselines.
19
Question
Why are wireless access point placement decisions security considerations?
Page 7
Answer
Wireless access point (WAP) placement is an installation consideration because placement is part of planning a wireless network installation.
20
Question
How do site surveys and heat maps support wireless installation?
Page 7
Answer
Site surveys and heat maps are wireless network installation considerations used to evaluate wireless coverage and assist with access point placement.
21
Question
Which wireless security options are identified in the configuration list?
Page 8
Answer
The list includes Open, WEP, WPS, WPA and WPA2, WPA3, Device Provisioning Protocol (DPP), Simultaneous Authentication of Equals (SAE), and Enhanced Open.
22
Question
How does DPP relate to WPS in wireless provisioning?
Page 8
Answer
Device Provisioning Protocol (DPP), also called “Easy Connect,” is identified as a replacement for WPS.
23
Question
What does SAE identify within WPA3 wireless security?
Page 8
Answer
Simultaneous Authentication of Equals (SAE) is identified as a WPA3 wireless authentication method.
24
Question
How does Enhanced Open fit into wireless security options?
Page 8
Answer
Enhanced Open is listed as a wireless security option alongside Open, WEP, WPS, WPA, WPA2, WPA3, DPP, and SAE.
25
Question
Which authentication method uses a WPA2 pre-shared key?
Page 9
Answer
WPA2 Pre-Shared Key Authentication uses a pre-shared key for wireless authentication.
26
Question
Which authentication method is specifically associated with WPA3 Personal?
Page 9
Answer
WPA3 Personal Authentication is the authentication method identified for WPA3 Personal wireless security.
27
Question
How does enterprise wireless authentication differ from personal authentication?
Page 9
Answer
The listed enterprise methods are WPA2/WPA3-Enterprise, RADIUS, and EAP. The personal methods listed are WPA2 Pre-Shared Key Authentication and WPA3 Personal Authentication.
28
Question
What roles do RADIUS and EAP have in wireless authentication?
Page 9
Answer
RADIUS and EAP are listed as Wi-Fi authentication methods associated with enterprise wireless authentication.
29
Question
What is the primary function of network access control?
Page 10
Answer
Network access control authenticates users and devices before allowing them access to the network.
30
Question
How do agent-based and agentless network access control differ?
Page 10
Answer
Network access control can use an agent or operate agentlessly. The listed distinction concerns whether endpoint software is used to support the access-control process.