County server admins must prove that hardened build settings still match an approved security baseline after each patch cycle. Which monitoring approach best automates that configuration-compliance check?
Select an answer to reveal the explanation.
Short Explanation
Think of SCAP benchmarks as a checklist the scanner can grade automatically—did each county server keep the approved locks on? Verbal meetings and hoping people read a PDF do not prove the boxes still match the baseline.
Full Explanation
SCAP (Security Content Automation Protocol) and related benchmarks enable automated assessment of configuration compliance against standardized checklists. Municipal operations use these scans after patching or rebuilds to detect drift from approved hardening settings. Informal walkthroughs or publishing documentation without verification leave gaps that monitoring is meant to close.