QuestionQ46

Security Engineering

A cybersecurity architect wants to strengthen vulnerability management and automate a large volume of vulnerability checks. Key constraints are:

  • There are 512 containerized microservices.
  • Vulnerability data comes from multiple scanners.
  • CIS baselines must be enforced.
  • Scan activity must be scheduled.

Which automation workflow best fulfills this objective?

Explanation

XCCDF provides a standardized format for security configuration checklists and benchmarks, enabling automated assessment against CIS baselines. An XCCDF-based scanner supports repeatable, schedulable configuration and vulnerability assessments at scale, whereas endpoint collection, CVSS reporting, and repository-only IaC scanning do not directly enforce those baselines across deployed services.

Community Discussion

No comments yet. Be the first to start the discussion!