CompTIA Server+ (SK0-005)Security and Disaster RecoveryEasy

A server administrator is implementing a new security policy that dictates all server configurations must be reviewed and approved before deployment to production. This policy aims to minimize potential vulnerabilities introduced by misconfigurations. Which of the following concepts is this policy primarily addressing?

  1. ADisaster Recovery Planning
  2. BAttack Surface Reduction
  3. CIdentity and Access Management
  4. DBusiness Continuity Planning
Show answer & explanation

Correct answer: B. Attack Surface Reduction

Reviewing server configurations before deployment helps identify and correct misconfigurations that could expose vulnerabilities. This proactive measure directly reduces the number of potential entry points for attackers, which is the core principle of attack surface reduction.

Why the other options are wrong

  • A. Disaster recovery planning focuses on recovering operations after a disaster, not preventing misconfigurations.
  • C. Identity and access management deals with who can access what resources, not the configuration of the resources themselves.
  • D. Business continuity planning ensures ongoing operations during disruptions, but doesn't specifically address configuration vulnerabilities.

Attack Surface Reduction

The process of minimizing the number of possible points of attack on a system, often by disabling unnecessary services, closing unused ports, and hardening configurations.

  • Reduces potential entry points for attackers.
  • Involves configuration hardening and disabling unneeded features.
  • A proactive security measure.

Memory trick: Shrink the attack surface, shrink the risk.

More Security and Disaster Recovery questions