Refer to the exhibit. An automated audit script returns the JSON configuration status for CIS Control 10. Based on this output, what is the most immediate security implication for the listed assets?
Exhibit
{
"control_id": "CIS_10",
"action": "Enable_Full_Disk_Encryption",
"status": "NON_COMPLIANT",
"affected_assets": ["WS-001", "WS-004", "SRV-09"]
}Trap 1: Unauthorized software has been installed on the listed assets.
The exhibit identifies a failure to enable encryption, not the presence of unauthorized applications. While unauthorized software is a security concern, the JSON object specifically flags encryption status, which is a data-at-rest protection mechanism unrelated to the application control or software integrity monitoring functions of the system.
Trap 2: The audit script failed to scan the network assets correctly.
There is no indication in the provided JSON to suggest a scanning error or a connectivity issue. The output provides specific asset identifiers (WS-001, WS-004, SRV-09) and a clear status, which implies the scan performed as expected, successfully identifying assets that do not meet the hardening requirements.
Trap 3: The assets are missing critical OS security patches.
The JSON explicitly references the action of enabling full disk encryption. It does not provide information regarding patch management status or vulnerability exposure levels. While missing patches represent a different security risk, this specific audit entry is focused entirely on the configuration of encryption services on disk.
- A
Unauthorized software has been installed on the listed assets.
Why it fails: The exhibit identifies a failure to enable encryption, not the presence of unauthorized applications. While unauthorized software is a security concern, the JSON object specifically flags encryption status, which is a data-at-rest protection mechanism unrelated to the application control or software integrity monitoring functions of the system.
- B
Data at rest is susceptible to unauthorized access if physical hardware is stolen.
Full disk encryption is specifically designed to protect data stored on physical drives. When this control is reported as non-compliant, it means the drives are unencrypted, leaving the data vulnerable to extraction by anyone with physical access to the device's storage media, regardless of password protections.
- C
The audit script failed to scan the network assets correctly.
Why it fails: There is no indication in the provided JSON to suggest a scanning error or a connectivity issue. The output provides specific asset identifiers (WS-001, WS-004, SRV-09) and a clear status, which implies the scan performed as expected, successfully identifying assets that do not meet the hardening requirements.
- D
The assets are missing critical OS security patches.
Why it fails: The JSON explicitly references the action of enabling full disk encryption. It does not provide information regarding patch management status or vulnerability exposure levels. While missing patches represent a different security risk, this specific audit entry is focused entirely on the configuration of encryption services on disk.