A systems administrator must deploy 200 new Windows workstations that all enforce the same approved registry, service, and password settings before going live. Which approach best establishes and consistently enforces this secure baseline?
A security template or GPO derived from an established benchmark codifies the approved settings and enforces them uniformly across every joined host.
- AManual per-host configuration is error prone and does not guarantee consistency at scale, defeating the purpose of a uniform baseline.
- CScanning finds missing patches and flaws but does not define or push the approved configuration settings that a baseline requires.
- DDefault vendor settings are exactly what hardening replaces; firewalls alone do not enforce the registry and service baseline needed here.