Identifying Security Baseline Documentation for Device Hardening
A security analyst is creating baselines for the server team to follow when hardening new devices for deployment. Which of the following best describes what the analyst is creating?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the hierarchy of security documentation; candidates must recognize that 'baselines' for 'hardening' are technical instructions found in a secure configuration guide, not broad policies.
This question tests the ability to distinguish between high-level policies and technical implementation guides. A secure configuration guide provides the specific baselines required for hardening devices.
Candidates often select Information Security Policy (B) because they associate 'guidelines' with policy documents, failing to realize that policies are high-level statements while hardening requires specific technical configurations.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Secure Configuration Guide (Option D) is the correct choice because it contains the specific technical settings, parameters, and best practices needed to harden systems. In the context of creating baselines for deployment, this document serves as the actionable reference for system administrators to ensure consistent security postures across new devices.Why the Other Options Are Wrong
Information Security Policy (Option B) defines the organization's overall goals and rules but lacks the granular technical details required for device hardening. Change Management Procedures (Option A) govern how changes are approved and tracked, not how systems are configured. Cybersecurity Frameworks (Option C) provide a high-level structure for managing risk, not step-by-step configuration instructions.Community Comment Notes
The community consensus strongly favors Option D. As noted by user Hs1208, a secure configuration guide provides detailed instructions for configuring systems securely. User Casperkey referenced the official study guide, stating that benchmarks and secure configuration guides are used as baselines for deploying assets. While one user suggested Policy (B), the technical nature of 'hardening' aligns definitively with configuration guides.Exam Strategy
When answering questions about 'hardening' or 'baseline' configurations, look for options that imply technical specificity like 'guide', 'benchmark', or 'profile'. Avoid 'policy' unless the question explicitly mentions governance, compliance, or high-level organizational rules.
Frequently Asked Questions
What is the difference between a security policy and a configuration guide?
A security policy is a high-level statement of management intent and rules. A configuration guide provides specific, technical instructions on how to set up systems to meet those rules.
Why is a cybersecurity framework not the right answer here?
Frameworks provide a structural approach to managing risk (like NIST or ISO). They do not contain the specific technical settings needed to harden individual servers or devices.