ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 472 - CAS-004 discussion

Report
Export

A company has identified a number of vulnerable, end-of-support systems with limited defensive capabilities. Which of the following would be the first step in reducing the attack surface in this environment?

A.
Utilizing hardening recommendations
Answers
A.
Utilizing hardening recommendations
B.
Deploying IPS/IDS throughout the environment
Answers
B.
Deploying IPS/IDS throughout the environment
C.
Installing and updating antivirus
Answers
C.
Installing and updating antivirus
D.
Installing all available patches
Answers
D.
Installing all available patches
Suggested answer: A

Explanation:

The first step in reducing the attack surface of vulnerable, end-of-support systems is to apply hardening recommendations. Hardening involves applying security configurations, such as disabling unnecessary services, enforcing strong authentication, and tightening access controls to mitigate vulnerabilities on systems that can no longer receive patches or support. While patching and deploying security tools like IPS/IDS and antivirus are important, hardening addresses the fundamental weakness of these legacy systems by reducing their exposure to threats. CASP+ recommends hardening as a crucial measure in environments where patching or upgrading may not be feasible, particularly for unsupported systems.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (System Hardening)

CompTIA CASP+ Study Guide: System Hardening for End-of-Life Systems

asked 02/10/2024
Brian Carlo Hubilla
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first