Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

An organization is performing a gap analysis against the CIS Controls. They find that while they have strong identity management, they fail to track the software installed on local machines, leading to 'shadow IT.' Which CIS Control should they implement to address this specific visibility gap?

⚠ Common exam trap

Candidates frequently select 'Control 1: Inventory of Enterprise Assets' instead of Control 2. They miss that the prompt specifically highlights 'software installed' rather than the hardware inventory itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CIS Control 2: Inventory and Control of Software Assets

The organization's issue involves a lack of visibility into what software is running on their endpoints, which is a classic symptom of failing CIS Control 2: Inventory and Control of Software Assets. By implementing this control, organizations can maintain an authoritative list of authorized software and detect unauthorized installations, ensuring that only approved, vetted applications exist on the network, thereby reducing the risk of malware and compliance violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CIS Control 1: Inventory and Control of Enterprise Assets

    Why it's wrong here

    Control 1 focuses on the inventory of physical hardware devices. While essential for overall visibility, it does not explicitly track the applications installed on those devices. The 'shadow IT' issue described is specifically related to software, which requires a software-centric inventory process to effectively mitigate the risk.

  • ✓

    CIS Control 2: Inventory and Control of Software Assets

    Why this is correct

    Control 2 requires maintaining an up-to-date inventory of all software installed on enterprise assets. This ensures that unauthorized software (shadow IT) can be detected and managed. By enforcing this control, security teams gain the visibility needed to authorize or remove applications, closing the gap described in the scenario.

  • ✗

    CIS Control 3: Data Protection

    Why it's wrong here

    Data protection focuses on the classification and security of data itself. While managing software is a prerequisite for protecting data, the primary control for visibility into installed software remains Control 2. Control 3 would not provide the necessary mechanisms to inventory and manage software applications across the environment.

  • ✗

    CIS Control 7: Continuous Vulnerability Management

    Why it's wrong here

    Vulnerability management relies on knowing what software is present, but it is not the control that establishes the inventory. Control 7 focuses on scanning for and remediating vulnerabilities within existing software. Without a solid foundation of software inventory (Control 2), vulnerability management efforts will be incomplete and ineffective.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.