CompTIA Security+ (SY0-701)Security OperationsEasy
A systems administrator is preparing a new server image for production. To reduce the attack surface, which action should be taken as part of the hardening process?
- AEnable all default services in case they are needed later
- BInstall every available vendor patch except security updates
- CDisable unused ports and services that are not required for the server's role
- DConfigure the server to accept remote management from any IP address
Show answer & explanationAnswer & explanation
Correct answer: C. Disable unused ports and services that are not required for the server's role
Hardening reduces the attack surface by disabling unnecessary services, ports, and protocols that are not needed for the system's function. Leaving unused services enabled or opening management access broadly increases exposure to attack.
Why the other options are wrong
- A. Enabling all defaults increases the attack surface rather than reducing it.
- B. Skipping security updates leaves known vulnerabilities unpatched.
- D. Unrestricted remote access increases risk instead of reducing it.
System Hardening
The process of reducing a system's attack surface by removing or disabling unnecessary features, services, ports, and default accounts.
- Disable unused services/ports
- Remove default accounts/credentials
- Apply security patches and baselines
- Use least functionality principle
Memory trick: Less running = less to attack.