Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is using OpenSCAP to perform a compliance scan against a set of RHEL servers. The analyst wants to ensure the servers comply with the CIS Benchmark Level 1 for Red Hat Enterprise Linux. What does Level 1 typically indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A set of security controls that are considered best practices with minimal impact on functionality

CIS Benchmarks define Level 1 as basic security requirements that can be implemented with minimal impact on functionality, while Level 2 includes more stringent controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A custom profile defined by the organization

    Why it's wrong here

    CIS Benchmarks, such as Level 1 and Level 2, are standardized, industry-accepted baselines developed by the Center for Internet Security, rather than custom profiles created internally by an organization. While OpenSCAP allows organizations to tailor profiles using tailoring files (.xml or .xccdf), the "Level 1" profile itself is a predefined, out-of-the-box standard.

  • ✓

    A set of security controls that are considered best practices with minimal impact on functionality

    Why this is correct

    The CIS Level 1 profile is specifically designed to provide a basic, highly effective reduction of an organization's attack surface while minimizing disruption to business operations and system utility. These consensus-based recommendations can be rapidly implemented across an enterprise without causing significant compatibility issues or administrative overhead.

  • ✗

    The most secure configuration possible

    Why it's wrong here

    The most secure configuration possible corresponds to a CIS Level 2 profile, which implements defense-in-depth measures and stricter security controls at the cost of some system functionality or ease of use. Level 1 is intended as a foundational baseline, whereas Level 2 is reserved for highly secure environments where the risk of operational disruption is acceptable.

  • ✗

    Configuration settings that are required for DoD environments

    Why it's wrong here

    United States Department of Defense (DoD) environments require compliance with the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) rather than CIS Benchmarks. While OpenSCAP can ingest both STIG and CIS profiles via SCAP Security Guide (SSG) data streams, they represent distinct regulatory frameworks with different compliance targets.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.