312-50V11 · Question #364
To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settings?
The correct answer is C. Hardening. System hardening is the process of reducing a system's attack surface by disabling unnecessary services, removing unneeded software, and correcting insecure default configuration settings.
Question
To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settings?
Options
- AHarvesting
- BWindowing
- CHardening
- DStealthing
How the community answered
(21 responses)- B5% (1)
- C90% (19)
- D5% (1)
Why each option
System hardening is the process of reducing a system's attack surface by disabling unnecessary services, removing unneeded software, and correcting insecure default configuration settings.
Harvesting is a reconnaissance technique used by attackers to collect email addresses, credentials, or data from targets, and is not a defensive configuration process.
Windowing is not a recognized information security process for reducing attack surfaces - it relates to networking concepts or UI paradigms.
Hardening is a well-defined security practice in which administrators systematically eliminate unnecessary attack vectors - including unneeded network services, unused software packages, default credentials, and weak configuration settings. By reducing the number of entry points and vulnerabilities present on a system, hardening directly lowers the risk of compromise and is a foundational element of both CIS Benchmarks and NIST security guidance.
Stealthing refers to techniques for concealing a system or its open ports from discovery, and does not involve removing unnecessary software or reconfiguring insecure settings.
Concept tested: System hardening to reduce attack surface
Source: https://csrc.nist.gov/glossary/term/hardening
Topics
Community Discussion
No community discussion yet for this question.