220-1002 · Question #4
A manager requests remote access to a server after hours and on weekends to check data. The manager insists on using the server. Before granting the access, which of the following is the MOST…
The correct answer is C. Ensure the server is patched with the latest security updates. Ensuring the server has the latest security patches is the most critical step because unpatched vulnerabilities are the primary attack vector that remote browsing activity can exploit.
Question
A manager requests remote access to a server after hours and on weekends to check data. The manager insists on using the server. Before granting the access, which of the following is the MOST important step a technician can take to protect against possible infection?
Options
- ACreate a policy to remove Internet access from the server during off hours
- BSet the local antivirus software on the server to update and scan daily
- CEnsure the server is patched with the latest security updates
- DEducate the manager on safe Internet browsing practices
How the community answered
(62 responses)- A3% (2)
- B10% (6)
- C82% (51)
- D5% (3)
Why each option
Ensuring the server has the latest security patches is the most critical step because unpatched vulnerabilities are the primary attack vector that remote browsing activity can exploit.
Removing Internet access during off hours is impractical because it prevents the manager from performing the very remote data checks that were requested.
Keeping antivirus updated and scanning daily is a good practice but is a compensating control - it is less effective than eliminating the underlying vulnerabilities through patching.
Patching closes known vulnerabilities in the OS and installed software that could be exploited if the manager visits a malicious site or unknowingly downloads malware. Without patches, even well-configured antivirus and browsing policies leave the server exposed to publicly documented exploits; patching is the foundational security control that must be in place before granting any remote access.
Educating the manager on safe browsing is a useful long-term measure but does not technically protect the server and does not address existing unpatched vulnerabilities.
Concept tested: Server hardening through patch management
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines
Topics
Community Discussion
No community discussion yet for this question.