Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard
A security team is deploying a new web application and needs to ensure the server hosting the application has a minimal attack surface. They decide to remove all unnecessary software, close all unneeded ports, and configure strong access controls. This approach is a direct application of which endpoint security concept?
- ALeast Functionality
- BDefense in Depth
- CSecurity by Obscurity
- DZero Trust
Show answer & explanationAnswer & explanation
Correct answer: A. Least Functionality
The principle of Least Functionality dictates that systems should only have the absolute minimum necessary services, applications, and ports enabled to perform their intended function, thereby reducing potential vulnerabilities and the attack surface.
Why the other options are wrong
- B. Defense in Depth involves layering multiple security controls, but 'removing unnecessary software' is a specific tactic under Least Functionality.
- C. Security by Obscurity relies on hiding information to secure it, which is generally a weak security practice, unlike the proactive hardening described.
- D. Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources, regardless of their location, not directly about minimizing software/ports.
Least Functionality
A security principle stipulating that systems should be configured with only the essential functions, services, and applications required for their intended purpose, thereby minimizing the attack surface.
- Reduces the number of potential vulnerabilities.
- Involves disabling unnecessary services and ports.
- A core component of system hardening.
Memory trick: Less is more when it comes to security features.