A security administrator is configuring a new web server and wants to ensure that the server's operating system and applications are hardened according to organizational standards. Which of the following should the administrator apply to enforce the desired security settings?
A security baseline is a documented set of minimum security settings that must be applied to a system to meet organizational policy. Applying it to the new web server ensures consistent hardening, reduces attack surface, and provides a known configuration to compare against during audits. It directly addresses the need to enforce desired security settings.
Why this answer
A security baseline provides the specific, documented configuration settings that must be applied to a system to meet security standards. It is the authoritative source for hardening a new server. The other options are important security processes but do not directly enforce the desired technical settings on the server.
Exam trap
The trap here is confusing procedural controls like change management with technical configuration baselines.