Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudEasy
A security analyst is investigating a recommendation in Microsoft Defender for Cloud that states, 'Management ports should be closed on Virtual Machines.' They notice that this recommendation has a high Secure Score impact. Which specific security principle is this recommendation primarily aiming to enforce to reduce the attack surface?
- ALeast Privilege Access
- BMinimizing Attack Surface
- CDefense in Depth
- DZero Trust Network Access
Show answer & explanationAnswer & explanation
Correct answer: B. Minimizing Attack Surface
Closing management ports on Virtual Machines directly reduces the number of potential entry points for attackers, which is a core principle of minimizing the attack surface.
Why the other options are wrong
- A. Least Privilege Access relates to user permissions, not network port exposure.
- C. Defense in Depth is a strategy using multiple layers of security, but 'closing ports' specifically targets the attack surface.
- D. Zero Trust Network Access is about verifying every access request, but the direct impact of closing ports is attack surface reduction.
Minimizing Attack Surface
A security principle focused on reducing the number of potential entry points or vulnerabilities that an attacker could exploit in a system, application, or network.
- Involves removing unnecessary services, ports, and features.
- Reduces the likelihood of successful exploitation.
- A fundamental concept in secure design.
- Example: closing unused network ports.
Memory trick: Closed ports reduce the attack, for security to come back.