CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard

A security engineer is performing a hardening review of a new server before it is deployed to production. The server will host a critical internal application and should only allow specific administrative access and the application's required network services. Which of the following is the MOST effective strategy to reduce the server's attack surface?

  1. ARegularly patching the operating system and installed applications.
  2. BDeploying an antivirus solution on the server.
  3. CImplementing a strong password policy for all user accounts.
  4. DEnabling a host-based firewall and configuring it to deny all incoming traffic by default, then explicitly allowing only necessary ports.
Show answer & explanation

Correct answer: D. Enabling a host-based firewall and configuring it to deny all incoming traffic by default, then explicitly allowing only necessary ports.

Enabling a host-based firewall and using a 'deny all, allow specific' rule set directly reduces the attack surface by closing unnecessary ports and services, preventing unauthorized network access to the server. This is a primary hardening technique.

Why the other options are wrong

  • A. Regular patching mitigates known vulnerabilities but does not inherently reduce the number of open ports or services (the attack surface).
  • B. Antivirus protects against malware but does not reduce the network attack surface by limiting open services or ports.
  • C. Strong passwords are crucial for authentication but do not directly reduce the network attack surface by closing ports or disabling services.

Attack Surface Reduction

The process of minimizing the number of possible points where an unauthorized user could try to enter or extract data from an environment.

  • Involves disabling unnecessary services/ports.
  • Reduces potential vulnerabilities.
  • A key part of server hardening.

Memory trick: Harden your server: less open, more secure.

More Security and Disaster Recovery questions