SK0-004 · Question #124
A technician would like to restrict when internal hardware components on the server are accessed. Which of the following server hardening techniques should the technician implement?
The correct answer is C. Chassis lock. A chassis lock is a physical security control that prevents unauthorized personnel from opening the server case and accessing internal hardware components.
Question
A technician would like to restrict when internal hardware components on the server are accessed. Which of the following server hardening techniques should the technician implement?
Options
- AIntrusion detection
- BBIOS password
- CChassis lock
- DDisable WOL
How the community answered
(16 responses)- B6% (1)
- C88% (14)
- D6% (1)
Why each option
A chassis lock is a physical security control that prevents unauthorized personnel from opening the server case and accessing internal hardware components.
Intrusion detection systems monitor network traffic or host activity for suspicious behavior and do not control physical access to server hardware components.
A BIOS password restricts access to firmware settings and boot order but does not prevent someone from physically opening the chassis and removing or tampering with internal hardware.
A chassis lock uses a physical keyed or padlock mechanism on the server case to prevent the chassis from being opened, directly restricting access to internal components such as drives, RAM, and expansion cards. This is a server hardening technique specifically designed to address physical security of internal hardware, which matches the technician's requirement exactly.
Disabling Wake-on-LAN removes a remote power-on attack surface but has no effect on whether someone can physically open and access the server's internal components.
Concept tested: Physical server hardening using chassis locks
Source: https://learn.microsoft.com/en-us/windows-server/security/security-and-assurance
Topics
Community Discussion
No community discussion yet for this question.