nerdexam
CompTIA

FC0-U61 · Question #269

When setting up a new device, there are multiple features available that will never be used. Which of the following should the user do to make the new device more secure?

The correct answer is B. Remove or disable the unnecessary features.. To enhance the security of a new device, a user should remove or disable any features that will not be used, thereby reducing the attack surface.

Security

Question

When setting up a new device, there are multiple features available that will never be used. Which of the following should the user do to make the new device more secure?

Options

  • AMake all users administrators.
  • BRemove or disable the unnecessary features.
  • CInstall a password manager on the device.
  • DMake all users guests.

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    87% (48)
  • C
    7% (4)
  • D
    4% (2)

Why each option

To enhance the security of a new device, a user should remove or disable any features that will not be used, thereby reducing the attack surface.

AMake all users administrators.

Making all users administrators grants them elevated privileges, increasing the risk if an account is compromised, rather than improving overall device security.

BRemove or disable the unnecessary features.Correct

Removing or disabling unnecessary features on a device reduces the attack surface by eliminating potential vulnerabilities associated with those features, making the system more secure.

CInstall a password manager on the device.

Installing a password manager helps users manage their passwords securely but does not directly secure the device itself by reducing its feature set or attack surface.

DMake all users guests.

Making all users guests restricts their privileges but doesn't address the underlying security risk posed by unnecessary features on the device for administrative accounts.

Concept tested: Principle of least functionality/attack surface reduction

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-security/least-privilege/

Topics

#device hardening#security best practices#attack surface reduction#least functionality

Community Discussion

No community discussion yet for this question.

Full FC0-U61 Practice