CompTIA SecurityX (CAS-005)Security EngineeringEasy
An organization is deploying a new web application and must ensure all server-side components, including the operating system, web server, and application runtime, are configured to minimize attack surface. Which of the following is a key server hardening practice that focuses on removing unnecessary software and services?
- AApplying security patches regularly
- BDisabling unnecessary services and removing unused software
- CImplementing strong password policies
- DConfiguring a host-based firewall
Show answer & explanationAnswer & explanation
Correct answer: B. Disabling unnecessary services and removing unused software
Disabling unnecessary services and removing unused software directly reduces the attack surface by eliminating potential vulnerabilities associated with those components. This is a fundamental principle of server hardening.
Why the other options are wrong
- A. Applying security patches regularly addresses known vulnerabilities but doesn't remove unnecessary software or services that might still expose the system.
- C. Implementing strong password policies is important for authentication but doesn't directly reduce the attack surface of the server's software components.
- D. Configuring a host-based firewall controls network access, which is a hardening step, but doesn't directly address unnecessary software/services already present on the system.
Server Hardening
The process of securing a server by reducing its attack surface, implementing security controls, and configuring it to operate with the highest level of security possible.
- Minimizes attack surface
- Removes unnecessary components
- Applies security configurations
- Protects against vulnerabilities
Memory trick: Hardening: Less is more for server security.