CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium

A security analyst is hardening a new Linux server. After installing the operating system and necessary applications, the analyst proceeds to remove or disable all unnecessary services and network ports. This action is a direct implementation of which security principle?

  1. ASeparation of Duties
  2. BDefense in Depth
  3. CPrinciple of Least Privilege
  4. DAttack Surface Reduction
Show answer & explanation

Correct answer: D. Attack Surface Reduction

Removing or disabling unnecessary services and network ports directly reduces the number of potential entry points that an attacker could exploit. This practice is known as attack surface reduction, as it shrinks the overall area available for attacks.

Why the other options are wrong

  • A. Separation of Duties divides critical tasks among multiple individuals to prevent fraud or error.
  • B. Defense in Depth involves multiple layers of security controls, not specifically disabling services.
  • C. Principle of Least Privilege applies to user/process permissions, not the server's services/ports.

Attack Surface Reduction

The practice of identifying and minimizing the number of possible points where an unauthorized user could try to enter or extract data from an environment, often by disabling unnecessary functionalities.

  • Reduces avenues for exploitation.
  • Involves disabling unused services and closing ports.
  • A fundamental hardening technique.

Memory trick: Shrink the attack surface, fewer places to get in.

More Security and Disaster Recovery questions