ISC2-CC - Security Operations - Section 5.2

Understand system hardening, including configuration management, patch management, and the use of baselines.

Apply system hardening by removing unnecessary services, applying secure baselines, and managing configuration changes so that systems do not drift from a known-good state. Recognise patch management as the disciplined application of vendor updates to close known vulnerabilities, and inventory and configuration management as its foundation.

System hardeningConfiguration managementPatch managementBaselines

Practice question for this objective

Free sampleSecurity Operationsmedium

A team lead wants to explain to stakeholders how configuration management differs from patch management, since the two are often mentioned together. Which statement best captures the essential difference?

  • AConfiguration management applies only to network devices, while patch management applies only to end-user workstations and servers
  • BConfiguration management is performed once at deployment, while patch management is the same activity repeated on a monthly schedule
  • CConfiguration management encrypts stored configuration files, while patch management verifies the digital signatures on those same files
  • DConfiguration management controls and tracks the approved settings and state of systems, while patch management specifically handles the deployment of vendor updates that fix flaws Correct
Configuration management governs approved system state broadly, while patch management is the narrower activity of deploying vendor fixes. Patch management is best understood as one activity within configuration management: applying a patch changes a system's state, so it must be tracked and controlled by the wider configuration management process rather than treated as a separate world.

Why A is wrong: This invents a device-based split that does not exist; both practices apply across servers, workstations, and network gear, so the distinction it draws is false.

Why B is wrong: Configuration management is a continuous discipline rather than a one-time task, and calling patch management merely a repeat of it collapses two distinct practices, so the description is inaccurate.

Why C is wrong: Encryption and signature checking are supporting security techniques, not the definitions of these disciplines, so this conflates specific mechanisms with the practices themselves and misses the real difference.

Why D is correct: Configuration management is the broad discipline of establishing, recording, and controlling approved system settings and changes; patch management is the narrower activity of testing and deploying vendor fixes, which is one input to that discipline.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Security Operations objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.