ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard

A software development team is adopting a 'Security by Design' approach for a new critical application. One of the key principles they are implementing is 'Minimizing the Attack Surface'. Which of the following actions best exemplifies this principle in practice during the design and development phases?

  1. AConducting regular penetration testing against the deployed application.
  2. BRemoving unnecessary features, services, and ports from the application and its underlying infrastructure.
  3. CImplementing robust logging and monitoring for all application activities.
  4. DEnsuring all input fields are thoroughly validated and sanitized.
Show answer & explanation

Correct answer: B. Removing unnecessary features, services, and ports from the application and its underlying infrastructure.

Minimizing the Attack Surface specifically refers to reducing the number of ways an attacker can interact with a system and potentially exploit vulnerabilities. Removing unnecessary features, services, and open ports directly achieves this by reducing the points of entry and potential weak links an attacker could target.

Why the other options are wrong

  • A. Penetration testing identifies vulnerabilities after the system is built, but it's a verification step, not a design principle for reducing the surface.
  • C. Logging and monitoring are crucial for detection and response, but they do not reduce the attack surface itself.
  • D. Input validation and sanitization prevent specific types of attacks (e.g., injection) but do not inherently remove features or services to reduce the overall surface.

Minimizing the Attack Surface

A security principle focused on reducing the number of potential points of entry or vulnerabilities that an attacker could use to compromise a system.

  • Achieved by removing unnecessary features, services, and code.
  • Involves closing unused ports and disabling unneeded protocols.
  • Reduces the overall complexity and potential exposure of a system.

Memory trick: Surface is Small, Security is Strong.

More Security Architecture and Engineering questions