CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium

A security engineer is hardening a new Linux server that will host a public-facing web application. To reduce the attack surface, which of the following actions should be prioritized?

  1. ADisabling or uninstalling all unnecessary services and applications.
  2. BConfiguring a robust firewall to block all unnecessary ports.
  3. CImplementing full disk encryption on all server volumes.
  4. DRegularly updating the operating system and application software.
Show answer & explanation

Correct answer: A. Disabling or uninstalling all unnecessary services and applications.

Disabling or uninstalling unnecessary services and applications directly reduces the attack surface by removing potential vulnerabilities and entry points that are not required for the server's function. While other options are important, this directly addresses the number of exploitable components.

Why the other options are wrong

  • B. A firewall is crucial but manages access to existing services, it doesn't remove the services themselves if they are running unnecessarily.
  • C. Full disk encryption protects data at rest but does not reduce the attack surface of a running system or its services.
  • D. Regular updates patch known vulnerabilities but don't eliminate unnecessary services that might still contain unknown vulnerabilities.

Attack Surface Reduction

The process of minimizing the number of possible points where an unauthorized user could try to enter or extract data from an environment.

  • Involves removing unnecessary functionality.
  • Reduces the number of exploitable vulnerabilities.
  • A key part of system hardening.

Memory trick: Close all doors, patch the walls, monitor the perimeter.

More Security and Disaster Recovery questions