CS0-003 Vulnerability Management Practice Question
A company uses a configuration management tool to enforce CIS Benchmarks on its servers. The security team wants to apply Level 1 benchmarks to all servers to achieve a baseline security posture. Which of the following best describes the difference between CIS Level 1 and Level 2 benchmarks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.
CIS Level 1 benchmarks are intended to provide a clear security benefit without significantly impacting functionality or performance. Level 2 benchmarks provide more stringent security but may reduce functionality or require additional operational effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Level 1 benchmarks are for Linux systems, while Level 2 benchmarks are for Windows systems.
Why it's wrong here
Level 1 and Level 2 profiles exist for nearly every operating system, including Linux, Windows, macOS, and various network devices. The distinction between the levels lies in the depth of hardening and potential operational impact, not the platform. Conflating benchmark levels with OS type misrepresents how CIS organizes its guidance.
- ✓
Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.
Why this is correct
CIS Benchmarks define Level 1 as the core set of security configurations that can be implemented without significantly degrading system functionality or causing incompatibility, making them suitable for most environments. Level 2 extends these settings with more aggressive hardening, such as disabling legacy protocols or tightening file permissions, which may reduce performance, break existing workflows, or require additional operational overhead. This performance-versus-restriction trade-off is the intended distinction.
- ✗
Level 1 benchmarks are for servers, while Level 2 benchmarks are for workstations.
Why it's wrong here
The Level 1/Level 2 designation is independent of the device's role; CIS issues benchmark profiles for servers, workstations, cloud instances, and other infrastructure, with both levels available within each profile. For example, a server benchmark and a workstation benchmark each contain their own Level 1 and Level 2 recommendations. Misclassifying levels as server-only or workstation-only ignores that the same security-grade scale applies across diverse device categories.
- ✗
Level 1 benchmarks are mandatory, while Level 2 benchmarks are optional.
Why it's wrong here
CIS benchmarks are consensus-based recommendations, not regulatory mandates; even Level 2 is optional and should be adopted only after assessing the organization's risk tolerance and operational requirements. Labeling Level 1 as mandatory would incorrectly suggest that CIS or a governing body enforces compliance, whereas in practice any benchmark profile is a baseline that an organization can tailor or extend. The distinction between levels reflects hardening depth, not legal or policy obligation.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.