ISC2-CC - Security Operations (18% of the exam) - Section 5.2

Understand system hardening, including configuration management, patch management, and the use of baselines.

Apply system hardening by removing unnecessary services, applying secure baselines, and managing configuration changes so that systems do not drift from a known-good state. Recognise patch management as the disciplined application of vendor updates to close known vulnerabilities, and inventory and configuration management as its foundation.

System hardeningConfiguration managementPatch managementBaselines

Practice question for this objective

Free sampleSecurity Operationsmedium

A team lead wants to explain to stakeholders how configuration management differs from patch management, since the two are often mentioned together. Which statement best captures the essential difference?

  • AConfiguration management applies only to network devices, while patch management applies only to end-user workstations and servers
  • BConfiguration management is performed once at deployment, while patch management is the same activity repeated on a monthly schedule
  • CConfiguration management encrypts stored configuration files, while patch management verifies the digital signatures on those same files
  • DConfiguration management controls and tracks the approved settings and state of systems, while patch management specifically handles the deployment of vendor updates that fix flaws Correct
Configuration management governs approved system state broadly, while patch management is the narrower activity of deploying vendor fixes. Patch management is best understood as one activity within configuration management: applying a patch changes a system's state, so it must be tracked and controlled by the wider configuration management process rather than treated as a separate world.

Why A is wrong: This invents a device-based split that does not exist; both practices apply across servers, workstations, and network gear, so the distinction it draws is false.

Why B is wrong: Configuration management is a continuous discipline rather than a one-time task, and calling patch management merely a repeat of it collapses two distinct practices, so the description is inaccurate.

Why C is wrong: Encryption and signature checking are supporting security techniques, not the definitions of these disciplines, so this conflates specific mechanisms with the practices themselves and misses the real difference.

Why D is correct: Configuration management is the broad discipline of establishing, recording, and controlling approved system settings and changes; patch management is the narrower activity of testing and deploying vendor fixes, which is one input to that discipline.

See more ISC2-CC practice questions, answers explained.

Exam traps in Security Operations

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Run a full antivirus scan on each laptop and then hand them out

    Why it is wrong: An antivirus scan checks for existing malware but tempting though it seems, it does not disable services or establish a consistent secure configuration across the fleet.

  • Incident response, which coordinates the containment and recovery activities that follow a confirmed security breach.

    Why it is wrong: Incident response handles events after a breach; the concern here is controlling routine changes before anything goes wrong.

  • Encrypting all data written to the server's disks so that stolen drives cannot be read by an unauthorised party

    Why it is wrong: Full-disk encryption protects data at rest and is a useful control, but it addresses confidentiality of stored data rather than reducing the system's attack surface, so it is not what hardening means.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.