CS0-003 Vulnerability Management Practice Question
An organization is implementing configuration management and decides to use CIS Benchmarks to harden their servers. They choose Level 1 benchmarks for most servers but Level 2 for highly sensitive systems. What is the key difference between Level 1 and Level 2 CIS benchmarks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Level 2 guidelines are more restrictive and may impact system functionality
CIS Level 1 benchmarks are basic security recommendations that can be implemented with minimal impact, while Level 2 includes more restrictive controls that may affect system functionality but provide higher security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Level 1 is more restrictive and secure than Level 2
Why it's wrong here
This reverses the actual CIS relationship: Level 1 defines baseline hardening settings that provide meaningful security benefit while minimizing the risk of breaking applications or services, making it the less restrictive, not more restrictive, of the two profiles.
- ✓
Level 2 guidelines are more restrictive and may impact system functionality
Why this is correct
Correct. Level 2 benchmarks apply defense-in-depth hardening intended for high-security environments and often disable features, ports, or services that could affect usability or compatibility, so CIS explicitly recommends testing Level 2 changes before production deployment due to potential functional impact.
- ✗
Level 1 is for cloud systems, Level 2 for on-premises
Why it's wrong here
CIS Benchmark levels are not scoped by deployment environment; both Level 1 and Level 2 profiles exist for cloud, on-premises, and hybrid platforms alike, and the distinction is based purely on hardening depth and risk tolerance, not on where the system is hosted.
- ✗
Level 2 is only for DoD environments
Why it's wrong here
This confuses two separate hardening frameworks: DISA STIGs are the Department of Defense-specific configuration standards, while CIS Benchmarks are published by the Center for Internet Security and Level 2 is simply their more stringent profile, with no organizational restriction to DoD environments.
Go deeper
Related to this question
Learn chapter
Privileged Access Management and PAM Tools
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.