SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A security analyst is hardening a Linux web server. The server hosts a critical application that processes sensitive customer data. The analyst needs to ensure that all non-essential services are disabled and that the system's attack surface is minimized. Which of the following actions best addresses this requirement?

  1. AConfigure a robust firewall to block all incoming traffic except for HTTP/HTTPS.
  2. BRegularly update the operating system and application software with the latest patches.
  3. CReview running services and disable those not required for the application's function.
  4. DInstall a host-based intrusion detection system (HIDS).
Show answer & explanation

Correct answer: C. Review running services and disable those not required for the application's function.

Disabling non-essential services directly reduces the attack surface by eliminating potential vulnerabilities associated with those services. While other options are good security practices, they do not directly address minimizing the attack surface by removing unnecessary components.

Why the other options are wrong

  • A. A firewall controls network access but doesn't remove services running internally on the server.
  • B. Patching addresses known vulnerabilities but doesn't remove unnecessary services that might still be exploited.
  • D. A HIDS monitors for malicious activity but doesn't reduce the attack surface itself.

Attack Surface Reduction

The process of identifying and reducing the number of possible attack vectors on a system or application.

  • Minimize open ports and services.
  • Disable unnecessary features and components.
  • Remove unused code or functionalities.

Memory trick: Hardening systems is like fortifying a castle: close all unnecessary gates.

More Systems and Application Security questions