An organization wants to enforce secure configurations consistently across 5,000 endpoints. Which approach MOST effectively ensures consistent hardening at scale?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because automated configuration management tools apply hardening consistently at scale, reduce human error, and enable continuous verification that configurations have not drifted from the baseline. B is wrong because manually configuring 5,000 endpoints is impractical, error-prone, and provides no ongoing enforcement against configuration drift.
Full explanation below image
Full Explanation
A is correct because automated configuration management tools apply hardening consistently at scale, reduce human error, and enable continuous verification that configurations have not drifted from the baseline. B is wrong because manually configuring 5,000 endpoints is impractical, error-prone, and provides no ongoing enforcement against configuration drift. C is wrong because default OS configurations include unnecessary services and permissive settings not hardened to security baselines. D is wrong because voluntary application of hardening at IT staff convenience does not ensure consistency across the environment.