What does system hardening involve?
- A.Reducing the attack surface by disabling unnecessary services, removing default accounts, applying patches, and configuring security settings
- B.Making hardware physically stronger; defence in depth means deploying the same control repeatedly at one layer, and adding controls at different layers weakens the posture by increasing the attack surface
- C.Adding more RAM to servers
- D.Increasing network bandwidth
Why A is correct
System hardening reduces vulnerabilities by: removing unnecessary software and services, changing default passwords, applying security patches, configuring firewalls, disabling unused ports, implementing least privilege, and following security benchmarks (CIS Benchmarks, DISA STIGs). A hardened system has a minimal attack surface.
Know someone studying for Security Fundamentals? Send them this one.