nerdexam
CompTIA

SK0-005 · Question #484

The HIDS logs on a server indicate a significant number of unauthorized access attempts via USB devices at startup. Which of the following steps should a server administrator take to BEST secure the s

The correct answer is B. Change the boot order on the server and restrict console access.. Changing the boot order on the server and restricting console access would prevent unauthorized access attempts via USB devices at startup, as the server would not boot from any external media and only authorized users could access the console. Setting a BIOS/UEFI password on the

Security and disaster recovery

Question

The HIDS logs on a server indicate a significant number of unauthorized access attempts via USB devices at startup. Which of the following steps should a server administrator take to BEST secure the server without limiting functionality?

Options

  • ASet a BIOS/UEFI password on the server.
  • BChange the boot order on the server and restrict console access.
  • CConfigure the host OS to deny login attempts via USB.
  • DDisable all the USB ports on the server.

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    74% (39)
  • C
    15% (8)
  • D
    4% (2)

Explanation

Changing the boot order on the server and restricting console access would prevent unauthorized access attempts via USB devices at startup, as the server would not boot from any external media and only authorized users could access the console. Setting a BIOS/UEFI password on the server would also help, but it could be bypassed by resetting the CMOS battery or using a backdoor password. Configuring the host OS to deny login attempts via USB would not prevent booting from a malicious USB device that could compromise the system before the OS loads. Disabling all the USB ports on the server would limit functionality, as some peripherals or devices may need to use them.

Topics

#Server security#Boot order#BIOS/UEFI#Physical security

Community Discussion

No community discussion yet for this question.

Full SK0-005 Practice