Courseiva
Vulnerability ManagementmediumMultiple ChoiceObjective-mapped

CS0-003 Vulnerability Management Practice Question

A company uses a configuration management tool to enforce CIS Benchmarks on its servers. The security team wants to apply Level 1 benchmarks to all servers to achieve a baseline security posture. Which of the following best describes the difference between CIS Level 1 and Level 2 benchmarks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.

CIS Level 1 benchmarks are intended to provide a clear security benefit without significantly impacting functionality or performance. Level 2 benchmarks provide more stringent security but may reduce functionality or require additional operational effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Level 1 benchmarks are for Linux systems, while Level 2 benchmarks are for Windows systems.

    Why it's wrong here

    Level 1 and Level 2 profiles exist for nearly every operating system, including Linux, Windows, macOS, and various network devices. The distinction between the levels lies in the depth of hardening and potential operational impact, not the platform. Conflating benchmark levels with OS type misrepresents how CIS organizes its guidance.

  • Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.

    Why this is correct

    CIS Benchmarks define Level 1 as the core set of security configurations that can be implemented without significantly degrading system functionality or causing incompatibility, making them suitable for most environments. Level 2 extends these settings with more aggressive hardening, such as disabling legacy protocols or tightening file permissions, which may reduce performance, break existing workflows, or require additional operational overhead. This performance-versus-restriction trade-off is the intended distinction.

  • Level 1 benchmarks are for servers, while Level 2 benchmarks are for workstations.

    Why it's wrong here

    The Level 1/Level 2 designation is independent of the device's role; CIS issues benchmark profiles for servers, workstations, cloud instances, and other infrastructure, with both levels available within each profile. For example, a server benchmark and a workstation benchmark each contain their own Level 1 and Level 2 recommendations. Misclassifying levels as server-only or workstation-only ignores that the same security-grade scale applies across diverse device categories.

  • Level 1 benchmarks are mandatory, while Level 2 benchmarks are optional.

    Why it's wrong here

    CIS benchmarks are consensus-based recommendations, not regulatory mandates; even Level 2 is optional and should be adopted only after assessing the organization's risk tolerance and operational requirements. Labeling Level 1 as mandatory would incorrectly suggest that CIS or a governing body enforces compliance, whereas in practice any benchmark profile is a baseline that an organization can tailor or extend. The distinction between levels reflects hardening depth, not legal or policy obligation.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.