3501
During an authorized retail-company assessment (RET-LAB-M13-3501), which action most directly controls the risk related to "secure web-server configuration"?
View answer choices
- Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
- Maintain a repeatable assessment process tied to asset value and risk ownership.
- Maintain tested playbooks, roles, communications, evidence handling, and exercises.
- Design overlapping controls across identity, endpoint, network, application, and data layers.