CompTIA SecurityX (CAS-005)Security EngineeringEasy
An organization is deploying a new web application and must ensure all server-side components are hardened according to industry best practices. Which of the following is a critical step in hardening a web server to minimize its attack surface?
- AInstalling the latest graphics drivers and desktop environment.
- BRemoving unnecessary software packages and disabling unused services.
- CEnabling all default services for maximum functionality.
- DConfiguring network interfaces to accept traffic on all ports.
Show answer & explanationAnswer & explanation
Correct answer: B. Removing unnecessary software packages and disabling unused services.
Removing unnecessary software and disabling unused services reduces the attack surface by eliminating potential vulnerabilities that could be exploited. This is a fundamental principle of server hardening.
Why the other options are wrong
- A. Graphics drivers and desktop environments are typically not needed on a web server and should be removed to reduce overhead and attack surface.
- C. Enabling all default services is a security risk as many may not be needed and introduce vulnerabilities.
- D. Configuring a server to accept traffic on all ports creates a massive attack surface and is a severe security misconfiguration.
Server Hardening
The process of securing a server by reducing its attack surface and mitigating vulnerabilities through configuration changes, software removal, and security controls.
- Minimize attack surface.
- Apply least privilege.
- Regularly patch and update.
Memory trick: Less is more for server security.