Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?

⚠ Common exam trap

Many candidates confuse Level 1 with 'maximum security' or assume it is only for critical systems, when in fact Level 1 is the baseline recommended for all systems to achieve a practical security posture without disrupting operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Basic security hygiene with minimal impact

CIS Benchmarks define Level 1 as a set of configuration settings intended to provide basic security hygiene with minimal impact on business operations. These settings are designed to be easily implemented without causing significant performance degradation or service disruption, making them suitable for most systems. Level 1 focuses on essential security controls that address common vulnerabilities while maintaining system usability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Maximum security with high operational impact

    Why it's wrong here

    Level 1 is the conservative baseline with minimal operational impact, so maximum security with high impact describes Level 2. It tempts because stronger hardening sounds desirable, but Level 2 settings can disrupt functionality and are reserved for high-security environments.

  • ✗

    Equivalent to DISA STIGs

    Why it's wrong here

    Level 1 is the baseline profile intended for all systems, not a mapping to DISA STIGs, which are separate DoD hardening guides with their own controls and audit procedures. It tempts because both are hardening baselines, yet they are distinct publications with different scopes.

  • ✗

    Only applicable to critical systems

    Why it's wrong here

    Level 1 applies to every system in scope, not only critical ones; that narrower targeting describes no CIS level. It tempts because critical assets often receive stricter baselines, but Level 1 is defined by low operational impact and broad applicability, not asset criticality.

  • ✓

    Basic security hygiene with minimal impact

    Why this is correct

    CIS Level 1 profiles apply settings intended as essential, low-risk hardening that can be deployed broadly with minimal disruption to functionality or performance. This matches the organisation's aim of implementing benchmarks across all Windows servers without breaking operational services.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.