Courseiva
Security Operations →mediumMultiple Choice

ISC2 CC Security Operations Practice Question

An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?

⚠ Common exam trap

It's easy for candidates to confuse preventive controls like patch management or change control with detective controls like automated configuration scanning, leading candidates to choose a process that does not actually detect drift.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated configuration scanning

Automated configuration scanning continuously compares each workstation's settings against a defined hardened baseline and flags deviations. It is the only option that provides ongoing detection of drift from the security configuration standard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch management

    Why it's wrong here

    Patch management remediates missing software updates; it does not compare workstation settings against a hardened baseline or flag deviations. It is tempting because patching is a core hardening activity and would be correct for closing known vulnerabilities, but detecting configuration drift requires continuous configuration assessment against the defined baseline.

  • ✗

    Change control

    Why it's wrong here

    Change control governs how modifications are requested, approved and documented; it does not scan endpoints or detect configuration drift from the hardened baseline. It is tempting because unauthorised changes often cause drift, and change control would be correct for preventing unapproved alterations, but detection needs configuration monitoring.

  • ✗

    Security awareness training

    Why it's wrong here

    Security awareness training educates staff about threats and policy; it neither inspects workstation configuration nor reports drift from the hardened baseline. It is tempting because training underpins a security culture, and it would be correct for reducing phishing susceptibility or improving incident reporting, not for technical baseline detection.

  • ✓

    Automated configuration scanning

    Why this is correct

    Automated configuration scanning continuously compares workstation settings against the defined hardened baseline and flags deviations. This satisfies the stem's requirement to detect when a workstation drifts from the baseline, rather than merely enforcing or remediating it.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.