ISC2 CC Security Operations Practice Question
An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?
⚠ Common exam trap
It's easy for candidates to confuse preventive controls like patch management or change control with detective controls like automated configuration scanning, leading candidates to choose a process that does not actually detect drift.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated configuration scanning
Automated configuration scanning continuously compares each workstation's settings against a defined hardened baseline and flags deviations. It is the only option that provides ongoing detection of drift from the security configuration standard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch management
Why it's wrong here
Patch management remediates missing software updates; it does not compare workstation settings against a hardened baseline or flag deviations. It is tempting because patching is a core hardening activity and would be correct for closing known vulnerabilities, but detecting configuration drift requires continuous configuration assessment against the defined baseline.
- ✗
Change control
Why it's wrong here
Change control governs how modifications are requested, approved and documented; it does not scan endpoints or detect configuration drift from the hardened baseline. It is tempting because unauthorised changes often cause drift, and change control would be correct for preventing unapproved alterations, but detection needs configuration monitoring.
- ✗
Security awareness training
Why it's wrong here
Security awareness training educates staff about threats and policy; it neither inspects workstation configuration nor reports drift from the hardened baseline. It is tempting because training underpins a security culture, and it would be correct for reducing phishing susceptibility or improving incident reporting, not for technical baseline detection.
- ✓
Automated configuration scanning
Why this is correct
Automated configuration scanning continuously compares workstation settings against the defined hardened baseline and flags deviations. This satisfies the stem's requirement to detect when a workstation drifts from the baseline, rather than merely enforcing or remediating it.
Go deeper
Related to this question
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.