SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A company is migrating its on-premises applications to a cloud environment. As part of the migration, they need to ensure that the virtual machines (VMs) are securely configured and hardened according to industry best practices. Which of the following is a critical step in hardening a cloud-based VM?

  1. ADisabling automated security updates to maintain system stability.
  2. BApplying the principle of least privilege to user accounts and service accounts.
  3. CEnabling unnecessary services and ports for future flexibility.
  4. DUsing default administrative credentials for ease of management.
Show answer & explanation

Correct answer: B. Applying the principle of least privilege to user accounts and service accounts.

Applying the principle of least privilege ensures that user and service accounts only have the minimum necessary permissions to perform their functions, significantly reducing the attack surface if an account is compromised.

Why the other options are wrong

  • A. Disabling automated security updates leaves the system vulnerable to known exploits and should be avoided; updates are crucial for security.
  • C. Enabling unnecessary services and ports increases the attack surface, making the VM less secure.
  • D. Using default credentials is a major security vulnerability and should always be avoided.

Cloud VM Hardening

The process of securing virtual machines in a cloud environment by reducing their attack surface, implementing strong configurations, and applying security best practices to protect against vulnerabilities and attacks.

  • Involves disabling unnecessary services, strong passwords, least privilege.
  • Includes regular patching and security updates.
  • Often guided by security benchmarks (e.g., CIS Benchmarks).

Memory trick: Harden the system, lock it down, make it strong throughout the town.

More Systems and Application Security questions