CS0-003 Vulnerability Management Practice Question
A security analyst is configuring a compliance scan for a Linux server using CIS Benchmarks. The analyst must ensure the server meets Level 1 benchmarks. Which of the following is a characteristic of CIS Level 1 benchmarks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are practical and prudent, with a low impact on business functionality
Level 1 benchmarks are foundational and designed to have minimal impact on business operations while improving security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They are practical and prudent, with a low impact on business functionality
Why this is correct
CIS Level 1 profiles are designed to provide a baseline of essential security configurations that can be rapidly implemented. These recommendations are practical, prudent, and engineered to minimize any adverse impact on business operations or system performance.
- ✗
They are only applicable to cloud environments
Why it's wrong here
CIS Benchmarks span a wide array of target systems, including on-premises operating systems, hypervisors, network devices, and desktop applications. They are not restricted to cloud environments, making this option far too narrow and technically inaccurate.
- ✗
They provide specific STIG requirements for DoD systems
Why it's wrong here
Security Technical Implementation Guides (STIGs) are distinct compliance standards published by the Defense Information Systems Agency (DISA) specifically for Department of Defense systems. While CIS Benchmarks can map to STIGs, they are separate frameworks maintained by different organizations.
- ✗
They are intended for high-security environments and may impact performance
Why it's wrong here
This statement describes CIS Level 2 profiles, which are intended for environments requiring defense-in-depth where security is prioritized over operational convenience. Level 2 recommendations implement stricter controls that may cause minor service disruptions or require extensive testing before deployment.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
Compliance scan
A compliance scan is an automated security assessment that checks systems, networks, and applications against a defined set of regulatory or organizational standards to verify adherence to required policies.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.