SSCP Risk Identification, Monitoring, and Analysis Practice Question
An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?
⚠ Common exam trap
Many candidates confuse Level 1 with 'maximum security' or assume it is only for critical systems, when in fact Level 1 is the baseline recommended for all systems to achieve a practical security posture without disrupting operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Basic security hygiene with minimal impact
CIS Benchmarks define Level 1 as a set of configuration settings intended to provide basic security hygiene with minimal impact on business operations. These settings are designed to be easily implemented without causing significant performance degradation or service disruption, making them suitable for most systems. Level 1 focuses on essential security controls that address common vulnerabilities while maintaining system usability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Maximum security with high operational impact
Why it's wrong here
Level 1 is the conservative baseline with minimal operational impact, so maximum security with high impact describes Level 2. It tempts because stronger hardening sounds desirable, but Level 2 settings can disrupt functionality and are reserved for high-security environments.
- ✗
Equivalent to DISA STIGs
Why it's wrong here
Level 1 is the baseline profile intended for all systems, not a mapping to DISA STIGs, which are separate DoD hardening guides with their own controls and audit procedures. It tempts because both are hardening baselines, yet they are distinct publications with different scopes.
- ✗
Only applicable to critical systems
Why it's wrong here
Level 1 applies to every system in scope, not only critical ones; that narrower targeting describes no CIS level. It tempts because critical assets often receive stricter baselines, but Level 1 is defined by low operational impact and broad applicability, not asset criticality.
- ✓
Basic security hygiene with minimal impact
Why this is correct
CIS Level 1 profiles apply settings intended as essential, low-risk hardening that can be deployed broadly with minimal disruption to functionality or performance. This matches the organisation's aim of implementing benchmarks across all Windows servers without breaking operational services.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.