Benchmarks
Windows
Securing Endpoints
Endpoint Hardening
100

These are used to guide the implementation of best practices in system hardening.

What are benchmarks?
100
Online tool used to visually map the attach surface of an organization.

What is draw.io?

100

These help to automate account management.

What is MSA (Managed Server Accounts)?

100

Hardening that secures Windows operating systems.

What is Windows OS hardening?

200

Website hosted by a non-profit group providing benchmarks for endpoint hardening.

What is CIS (Center for Internet Security)?
200

These objects are used to enforce security policies on Windows endpoints.

What are Group Policy Objects (GPOs)

200

The provides multiple forms of verification to enhance security.

What is MFA (Multi-factor authentication?

200

This type of data pertains to social security numbers, names, addresses, birth dates, phone numbers, and e-mail addresses.

What is personal identifying information (PII)?

300
These help to ensure compliance with security standards.

What are regular assessments?

300

Type of attack that targets tickets and can be mitigated by using strong passwords on service accounts.

What are Kerberoasting attacks?

300

A protocol used by employees to remotely connect to their workstations that should be limited to reduce attack vectors.

What is RDP (Remote Desktop Protocol)?

300

This type of information includes patents, trade secrets, and proprietary information.

What is intellectual property (IP)?

400

A scoring system given to vulnerabilities used to rate their level of risk.

What is CVSS (common vulnerability scoring system)?

400

Network protocol used to share files and resourced between computers that attackers can use for lateral movement.

What is SMB (Server Message Block)

400

Limits user access to resources based solely on their role.

What is RBAC (Role Based Access Control)?

400

Type of data includes bank account details and credit card numbers.

What is Financial Data?

500

The program to identify, define, and catalog publicly disclosed cyber security vulnerabilities.

What is CVE (Common Vulnerabilities and Exposures)?

500

A cloud based automated hardening tool from Microsoft.

What is Intune?

500

Ways an organization can address user resistance to security configurations.

What is training and support?

500

The entire range of endpoints in an organization that need to be hardened against attacks and the primary purpose that endpoint hardening attempts to reduce. 

What is the attack surface?

M
e
n
u