Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A security administrator is configuring a new web server. Following the principle of least functionality, which of the following actions should the administrator take?
- AGrant all users administrative privileges to simplify management.
- BInstall all available server roles and features to ensure future flexibility.
- CKeep default configurations for all services to ensure compatibility.
- DDisable all unnecessary services, ports, and protocols not required for the web server's function.
Show answer & explanationAnswer & explanation
Correct answer: D. Disable all unnecessary services, ports, and protocols not required for the web server's function.
The principle of least functionality dictates that systems should only have the absolute minimum necessary functions, services, and applications enabled. Disabling unnecessary components reduces the attack surface and potential vulnerabilities.
Why the other options are wrong
- A. Granting excessive privileges violates the principle of least privilege, not least functionality directly.
- B. Installing all features violates least functionality by increasing the attack surface.
- C. Keeping default configurations is a security risk, as defaults are often insecure and do not follow least functionality.
Least Functionality
A security principle that states a system should be configured to provide only the essential functions required for its intended purpose, with all unnecessary features, services, and applications disabled or removed.
- Reduces the attack surface by minimizing potential entry points for attackers.
- Decreases the likelihood of vulnerabilities associated with unused components.
- Simplifies system management and auditing by having fewer active parts.
Memory trick: Less is more for security – only what's absolutely needed, nothing extra.