CompTIA SecurityX (CAS-005)Security EngineeringEasy

An organization is deploying a new web application and must ensure all server-side components are hardened according to industry best practices. Which of the following is a critical step in hardening a web server to minimize its attack surface?

  1. AInstalling the latest graphics drivers and desktop environment.
  2. BRemoving unnecessary software packages and disabling unused services.
  3. CEnabling all default services for maximum functionality.
  4. DConfiguring network interfaces to accept traffic on all ports.
Show answer & explanation

Correct answer: B. Removing unnecessary software packages and disabling unused services.

Removing unnecessary software and disabling unused services reduces the attack surface by eliminating potential vulnerabilities that could be exploited. This is a fundamental principle of server hardening.

Why the other options are wrong

  • A. Graphics drivers and desktop environments are typically not needed on a web server and should be removed to reduce overhead and attack surface.
  • C. Enabling all default services is a security risk as many may not be needed and introduce vulnerabilities.
  • D. Configuring a server to accept traffic on all ports creates a massive attack surface and is a severe security misconfiguration.

Server Hardening

The process of securing a server by reducing its attack surface and mitigating vulnerabilities through configuration changes, software removal, and security controls.

  • Minimize attack surface.
  • Apply least privilege.
  • Regularly patch and update.

Memory trick: Less is more for server security.

More Security Engineering questions