Study. uk . com
  1. Home
  2. All questions
  3. Question 202

CISSP study material · question 202 of 500

Which three pieces of information does a continuous diagnostics and mitigation system supply to the policy engine about a requesting asset? Choose three.

  1. Whether enterprise-approved software components remain intact.
  2. Whether the asset carries any known vulnerabilities.
  3. Whether the subject has completed security awareness training.
  4. Whether the operating system is appropriately patched.
Show the answer

Answer: B. Whether the asset carries any known vulnerabilities.
D. Whether the operating system is appropriately patched.
A. Whether enterprise-approved software components remain intact.

The diagnostics system reports the asset's current state to the engine: patching, the integrity of approved software or the presence of unapproved components, and known vulnerabilities.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 3 Logical Components, CDM system

Challenge yourself on this topic → Study as cards