Identifying Security Baseline Documentation for Device Hardening

Security Policies and Standards
Answer Correct answer: D — The analyst is creating a Secure Configuration Guide to provide specific technical baselines for hardening new devices during deployment.

A security analyst is creating baselines for the server team to follow when hardening new devices for deployment. Which of the following best describes what the analyst is creating?

  1. Change management procedure
  2. Information security policy
  3. Cybersecurity framework
  4. Secure configuration guide Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the hierarchy of security documentation; candidates must recognize that 'baselines' for 'hardening' are technical instructions found in a secure configuration guide, not broad policies.

This question tests the ability to distinguish between high-level policies and technical implementation guides. A secure configuration guide provides the specific baselines required for hardening devices.

Candidates often select Information Security Policy (B) because they associate 'guidelines' with policy documents, failing to realize that policies are high-level statements while hardening requires specific technical configurations.

Community Discussion (6 comments)

shady23 👍 1 Selected: D
D. Secure configuration guide
Casperkey 👍 3 Selected: D
From CompTIA Security+ Student Guide - Lesson 1 "Use benchmarks, secure configuration guides, and development best practices as baselines for deploying assets."
LuckyAro 👍 1 Selected: B
Chat GPT is not always correct !! These are Chat GPT answers and very misleading, we need to study the material. The correct answer is B in my opinion. I think all the knowledgeable guys have left this platform after passing the test ....... I need to leave too ! Lol
salah112 👍 3 Selected: D
D. Secure configuration guide When a security analyst is creating baselines for the server team to follow when hardening new devices for deployment, they are likely creating a document that provides guidelines and recommendations for securely configuring and hardening the devices. This type of document is commonly referred to as a "Secure Configuration Guide."
7308365 👍 1
D. After installing an operating system, web server, database server, or almost any other kind of technology, you always want to make sure it has a secure configuration. To make sure it has a secure configuration, you would "harden the system." Through creating baselines for the server team to follow when hardening new devices for deployment, this security analyst is creating secure configuration guides. https://www.professormesser.com/security-plus/sy0-501/secure-configuration-guides/
Hs1208 👍 4 Selected: D
Secure configuration guide (Option D): A secure configuration guide provides detailed instructions and recommendations for configuring systems and devices in a secure manner. It typically includes settings, parameters, and best practices to follow when hardening devices. This aligns with the task of creating baselines for the server team.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Secure Configuration Guide (Option D) is the correct choice because it contains the specific technical settings, parameters, and best practices needed to harden systems. In the context of creating baselines for deployment, this document serves as the actionable reference for system administrators to ensure consistent security postures across new devices.

Why the Other Options Are Wrong

Information Security Policy (Option B) defines the organization's overall goals and rules but lacks the granular technical details required for device hardening. Change Management Procedures (Option A) govern how changes are approved and tracked, not how systems are configured. Cybersecurity Frameworks (Option C) provide a high-level structure for managing risk, not step-by-step configuration instructions.

Community Comment Notes

The community consensus strongly favors Option D. As noted by user Hs1208, a secure configuration guide provides detailed instructions for configuring systems securely. User Casperkey referenced the official study guide, stating that benchmarks and secure configuration guides are used as baselines for deploying assets. While one user suggested Policy (B), the technical nature of 'hardening' aligns definitively with configuration guides.

Exam Strategy

When answering questions about 'hardening' or 'baseline' configurations, look for options that imply technical specificity like 'guide', 'benchmark', or 'profile'. Avoid 'policy' unless the question explicitly mentions governance, compliance, or high-level organizational rules.

Frequently Asked Questions

What is the difference between a security policy and a configuration guide?

A security policy is a high-level statement of management intent and rules. A configuration guide provides specific, technical instructions on how to set up systems to meet those rules.

Why is a cybersecurity framework not the right answer here?

Frameworks provide a structural approach to managing risk (like NIST or ISO). They do not contain the specific technical settings needed to harden individual servers or devices.

Related Analysis

← Back to SY0-601 Study Guide