CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard

A server administrator discovers a potential zero-day vulnerability in a critical operating system component. To mitigate the risk before an official patch is released, which hardening technique would be most effective in preventing exploitation?

  1. AConfiguring antivirus software to perform daily full scans.
  2. BEnabling full disk encryption on the server's boot drive.
  3. CDisabling unnecessary network protocols and services.
  4. DImplementing a strong password policy for all user accounts.
Show answer & explanation

Correct answer: C. Disabling unnecessary network protocols and services.

Disabling unnecessary network protocols and services directly reduces the attack surface. If the zero-day vulnerability exists in a service or protocol that is not essential for the server's function, disabling it will prevent an attacker from exploiting that specific entry point, even without a patch.

Why the other options are wrong

  • A. Antivirus software is primarily effective against known malware, not typically against a zero-day vulnerability before detection signatures are available.
  • B. Full disk encryption protects data at rest but does not prevent the exploitation of a running OS vulnerability.
  • D. Strong password policies are essential but do not directly prevent the exploitation of a zero-day OS vulnerability.

Zero-Day Vulnerability Mitigation

Techniques used to reduce the risk of exploitation from a newly discovered software vulnerability for which no official patch exists yet.

  • Focus on attack surface reduction.
  • Implement compensating controls.
  • Requires vigilance and proactive measures.

Memory trick: Block the paths, reduce the targets, monitor for anomalies.

More Security and Disaster Recovery questions