Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

A healthcare provider is aligning its security program with the CIS Critical Security Controls. The security team is tasked with implementing CIS Control 1: Inventory and Control of Enterprise Assets. Which of the following activities is the most critical first step to ensure the control is effectively implemented?

⚠ Common exam trap

The trap here is focusing on the technical tool (such as an automated discovery tool or CMDB) as the first step, while overlooking the need for policy and ownership definition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating a formal policy that defines what constitutes an enterprise asset and assigns ownership for maintaining the inventory.

CIS Control 1 emphasizes the importance of a formalized process for inventory and control of enterprise assets. The initial step is to create a policy that defines the scope and assigns ownership. This ensures that the inventory is accurate, maintained, and aligned with organizational needs. Without this governance, technical implementations may lack direction and accountability, leading to an ineffective control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Creating a formal policy that defines what constitutes an enterprise asset and assigns ownership for maintaining the inventory.

    Why this is correct

    CIS Control 1 begins with establishing and maintaining an inventory of enterprise assets. The foundational step is to define the scope and create a policy that specifies what assets are in scope, who owns them, and how the inventory will be maintained. This ensures that subsequent technical steps, like discovery and tracking, are aligned with business requirements and have clear accountability.

  • ✗

    Deploying an automated asset discovery tool to scan the network for all connected devices.

    Why it's wrong here

    While automated discovery is important, it is not the first step. Without a defined process and ownership, the tool may produce incomplete or unmanaged data. The CIS Control 1 requires establishing and maintaining an accurate, detailed, and up-to-date inventory. The first step is to define the scope and responsibilities, then use tools to support the process.

  • ✗

    Implementing a configuration management database (CMDB) to store asset information.

    Why it's wrong here

    A CMDB is a tool that can support the inventory, but it is not the first step. Without a policy defining scope and ownership, the CMDB may be populated with irrelevant or incomplete data. The CIS Control emphasizes the process and governance before tooling. A CMDB is useful but should follow the establishment of requirements and responsibilities.

  • ✗

    Conducting a manual inventory of all assets in the data center.

    Why it's wrong here

    Manual inventory can be error-prone and quickly outdated. While it might provide a starting point, it is not the most critical first step. The CIS Control requires an automated, accurate, and maintained inventory. Manual efforts alone cannot keep pace with changes. The first step should be to define the policy and scope, then implement automated discovery and tracking.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.