Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A developer workstation is configured with multiple virtual machines (VMs) for testing different application versions. To minimize the attack surface, the security team recommends ensuring that each VM is isolated from the host OS and other VMs as much as possible, and that unnecessary services are disabled. This aligns with which endpoint security best practice?
- ASecure Configuration Baseline
- BPrinciple of Least Privilege
- CDefense in Depth
- DNetwork Segmentation
Show answer & explanationAnswer & explanation
Correct answer: A. Secure Configuration Baseline
Ensuring isolation, disabling unnecessary services, and generally hardening the configuration of each VM and the host OS aligns with establishing and maintaining a secure configuration baseline, which reduces the attack surface.
Why the other options are wrong
- B. Least Privilege relates to user or process permissions, not directly the hardening of system configurations or isolation of VMs.
- C. Defense in Depth is a strategy of layering multiple security controls, but 'disabling unnecessary services' and 'isolation' are specific tactics within a secure configuration baseline.
- D. Network Segmentation separates networks, while VM isolation is more about host-level separation and configuration.
Secure Configuration Baseline
A standardized set of security configurations and settings applied to systems and devices to reduce vulnerabilities and establish a secure starting point.
- Involves disabling unnecessary services and features.
- Applies security patches and updates.
- Reduces the attack surface of systems.
Memory trick: A secure baseline is like a strong foundation for your house.