CAS-005 · Question #308
An organization recently implemented a purchasing freeze that has impacted endpoint life-cycle management efforts. Which of the following should a security manager do to reduce risk without…
The correct answer is A. Remove unneeded services. An organization faces a purchasing freeze impacting endpoint life-cycle management, requiring a security manager to reduce risk on existing endpoints without replacement.
Question
An organization recently implemented a purchasing freeze that has impacted endpoint life-cycle management efforts. Which of the following should a security manager do to reduce risk without replacing the endpoints?
Options
- ARemove unneeded services
- BDeploy EDR
- CDispose of end-of-support devices
- DReimage the system
How the community answered
(30 responses)- A83% (25)
- B3% (1)
- C3% (1)
- D10% (3)
Why each option
An organization faces a purchasing freeze impacting endpoint life-cycle management, requiring a security manager to reduce risk on existing endpoints without replacement.
Removing unneeded services reduces the attack surface of an endpoint by eliminating potential vulnerabilities associated with unnecessary running software or open ports. This is a practical and cost-effective measure to reduce risk when new equipment cannot be purchased.
Deploying EDR, while beneficial, typically incurs costs for licenses, deployment, and management, which might be impacted by a purchasing freeze.
Disposing of end-of-support devices would necessitate replacing them, which directly contradicts the constraint of not replacing endpoints due to a purchasing freeze.
Reimaging the system refreshes its state and can remove malware but does not fundamentally reduce the inherent attack surface if unneeded services are still present and running.
Concept tested: Endpoint hardening and attack surface reduction
Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/hardensd/
Community Discussion
No community discussion yet for this question.