4.1 Given a scenario, apply common security techniques to computing resources

Domain 4: Security Operations

This objective tests whether you can pick the right hardening or protection technique for a specific computing resource: mobile devices, workstations, servers, cloud workloads, IoT and embedded systems, and wireless networks. Expect scenario questions that hand you a device type and a constraint, then ask which control fits. Know secure baselines and how they are established, deployed, and maintained; mobile deployment models (BYOD, COPE, CYOD) and MDM capabilities; wireless security including WPA3, RADIUS, and 802.1X enterprise authentication; and application security techniques like input validation, code signing, and sandboxing. Candidates often prepare only for traditional endpoints and get caught by embedded, RTOS, and SCADA scenarios where patching is constrained and compensating controls such as segmentation matter more. Also be ready to distinguish site surveys and heat maps from configuration controls, and to explain why default credentials, unnecessary services, and open ports appear in almost every hardening answer. When two options both improve security, choose the one that matches the stated resource and constraint.

What you must know

common pitfall · Candidates apply desktop-style hardening answers to embedded or IoT scenarios instead of choosing compensating controls like segmentation when patching is not realistic.

Try a sample question

A systems administrator must deploy 200 new Windows workstations. Security policy requires that every workstation start from an identical, hardened configuration with unnecessary services disabled and required registry settings applied before users receive the machines. Which of the following should the administrator use to meet this requirement?

  • A A host-based firewall enabled on each machine
  • B A secure baseline image applied during provisioning
  • C Full-disk encryption enforced through group policy
  • D An endpoint detection and response agent
Show answer & explanations
  • A A host-based firewall protects individual machines from network threats but does not establish a consistent hardened configuration with disabled services and required registry settings across all workstations.
  • B correct ·A secure baseline image captures the approved hardened configuration once, so every workstation provisioned from it starts identical, with unnecessary services already disabled and mandated settings already applied.
  • C Full-disk encryption protects data at rest if a device is lost or stolen, but it does not disable services or enforce the hardened configuration settings the policy requires.
  • D An endpoint detection and response agent detects and responds to malicious activity after deployment; it does not provide the identical hardened starting configuration required before machines reach users.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 4.1 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free