Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A security auditor is performing a vulnerability assessment on a company's internal network. They discover that several servers are running services with default credentials and unnecessary open ports. Which of the following network security best practices would address these specific findings?
- AImplementing strong encryption for all data in transit
- BEstablishing comprehensive incident response plans
- CUtilizing a robust network intrusion detection system
- DRegularly hardening systems and services
Show answer & explanationAnswer & explanation
Correct answer: D. Regularly hardening systems and services
Hardening systems and services involves configuring them securely by changing default credentials, closing unnecessary ports, disabling unused services, and applying security best practices to reduce the attack surface.
Why the other options are wrong
- A. Strong encryption protects data confidentiality during transmission but does not address vulnerabilities like default credentials or unnecessary open ports on a server itself.
- B. Incident response plans guide actions after a breach occurs; they are reactive and do not prevent initial vulnerabilities from existing on systems.
- C. A robust IDS detects attacks but does not prevent the existence of vulnerabilities like default credentials or open ports; it's a detective control.
System Hardening
The process of securing a system by reducing its attack surface, eliminating potential vulnerabilities, and implementing security controls.
- Includes changing default credentials, disabling unnecessary services, and closing unused ports.
- Applies to operating systems, applications, and network devices.
- A continuous process, not a one-time activity.
Memory trick: Make your systems tough, like a well-armored knight.