CompTIA SecurityX (CAS-005)Security EngineeringEasy
An organization is deploying a new web application and must ensure all server-side components (operating system, web server, database) are configured securely according to industry best practices. This involves applying security patches, disabling unnecessary services, removing default accounts, and configuring secure access controls. This comprehensive process is known as:
- AVulnerability Scanning
- BServer Hardening
- CSecurity Auditing
- DPenetration Testing
Show answer & explanationAnswer & explanation
Correct answer: B. Server Hardening
Server hardening is the process of securing a server by reducing its attack surface, which involves applying patches, disabling unnecessary services, configuring secure access controls, and other security best practices.
Why the other options are wrong
- A. Vulnerability scanning identifies weaknesses but doesn't implement the fixes.
- C. Security auditing reviews configurations and logs for compliance and security issues, but it's not the active process of securing the server itself.
- D. Penetration testing simulates attacks to find vulnerabilities, but isn't the process of applying baseline security.
Server Hardening
The process of securing a server by reducing its attack surface, typically involving applying patches, disabling unnecessary services, removing default configurations, and implementing strong access controls.
- Reduces attack surface
- Applies security best practices
- Crucial first step in securing any server
Memory trick: Hardening Makes Servers Strong, Not Soft.