CS0-003 Vulnerability Management Practice Question
A security analyst is using OpenSCAP to perform a compliance scan against a set of RHEL servers. The analyst wants to ensure the servers comply with the CIS Benchmark Level 1 for Red Hat Enterprise Linux. What does Level 1 typically indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A set of security controls that are considered best practices with minimal impact on functionality
CIS Benchmarks define Level 1 as basic security requirements that can be implemented with minimal impact on functionality, while Level 2 includes more stringent controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A custom profile defined by the organization
Why it's wrong here
CIS Benchmarks, such as Level 1 and Level 2, are standardized, industry-accepted baselines developed by the Center for Internet Security, rather than custom profiles created internally by an organization. While OpenSCAP allows organizations to tailor profiles using tailoring files (.xml or .xccdf), the "Level 1" profile itself is a predefined, out-of-the-box standard.
- ✓
A set of security controls that are considered best practices with minimal impact on functionality
Why this is correct
The CIS Level 1 profile is specifically designed to provide a basic, highly effective reduction of an organization's attack surface while minimizing disruption to business operations and system utility. These consensus-based recommendations can be rapidly implemented across an enterprise without causing significant compatibility issues or administrative overhead.
- ✗
The most secure configuration possible
Why it's wrong here
The most secure configuration possible corresponds to a CIS Level 2 profile, which implements defense-in-depth measures and stricter security controls at the cost of some system functionality or ease of use. Level 1 is intended as a foundational baseline, whereas Level 2 is reserved for highly secure environments where the risk of operational disruption is acceptable.
- ✗
Configuration settings that are required for DoD environments
Why it's wrong here
United States Department of Defense (DoD) environments require compliance with the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) rather than CIS Benchmarks. While OpenSCAP can ingest both STIG and CIS profiles via SCAP Security Guide (SSG) data streams, they represent distinct regulatory frameworks with different compliance targets.
Go deeper
Related to this question
Learn chapter
Compliance Reporting
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.