nerdexam
CompTIA

SK0-004 · Question #419

A datacenter recently experienced a breach committed by a group that was able to access a server that had been shut down but not disconnected from the network. Which of the following could have…

The correct answer is A. Disabling WOL in the server BIOS. A powered-off server that remains network-connected can be remotely powered on via Wake-on-LAN (WOL), which sends a 'magic packet' to trigger the boot sequence. Disabling WOL in the BIOS eliminates this remote power-on attack vector.

Security and disaster recovery

Question

A datacenter recently experienced a breach committed by a group that was able to access a server that had been shut down but not disconnected from the network. Which of the following could have prevented the breach from occurring?

Options

  • ADisabling WOL in the server BIOS
  • BShutting down unneeded ports on the server
  • CInstalling anti-malware software on the server
  • DDisabling non-essential services on the server

How the community answered

(40 responses)
  • A
    80% (32)
  • B
    13% (5)
  • C
    3% (1)
  • D
    5% (2)

Why each option

A powered-off server that remains network-connected can be remotely powered on via Wake-on-LAN (WOL), which sends a 'magic packet' to trigger the boot sequence. Disabling WOL in the BIOS eliminates this remote power-on attack vector.

ADisabling WOL in the server BIOSCorrect

Wake-on-LAN is a BIOS-level feature that listens for a specially crafted 'magic packet' on the network interface even when the server is powered off, allowing the machine to be turned on remotely. Since the breached server was shut down but still network-connected, an attacker could have sent a WOL magic packet to power it on and gain access. Disabling WOL in the BIOS removes this capability entirely, regardless of network connectivity.

BShutting down unneeded ports on the server

Shutting down unneeded OS-level ports is irrelevant because the server was already powered off and no operating system or network services were running.

CInstalling anti-malware software on the server

Anti-malware software requires an active OS to function and cannot protect a powered-off server from being remotely powered on via a hardware-level feature.

DDisabling non-essential services on the server

Disabling non-essential services only applies when the server is running; a powered-off server has no active services that can be disabled or exploited.

Concept tested: Wake-on-LAN BIOS feature as a security vulnerability

Topics

#Wake-on-LAN#WOL#BIOS security#physical security

Community Discussion

No community discussion yet for this question.

Full SK0-004 Practice