Soru

Zorluk: OrtaWorkstation Hardening and Best Practices

An IT technician is hardening standalone Windows desktops used in a shared laboratory environment. To minimize the system's vulnerability to unauthorized network-based administrative access and remote configuration changes, the technician needs to disable non-essential background services. Which of the following services should be disabled to prevent remote users from modifying the system registry over the network?

  1. Remote RegistryCevap
  2. B
    Task Scheduler
  3. C
    Windows Management Instrumentation (WMI)
  4. D
    Credential Manager

Cevap

Disabling the Remote Registry service is the best workstation hardening practice to stop unauthorized remote registry modifications over the network.
Disabling the Remote Registry service prevents users across the network from querying or altering the local Windows registry, directly reducing the workstation's remote attack surface without impacting normal local user operations.

Adım Adım Çözüm

1
Identify the primary security objective described in the scenario.
The objective is to harden the workstation by disabling unnecessary network services that allow remote administrative tampering.
Workstation hardening follows the principle of least functionality by disabling services that expose network vulnerabilities.
2
Evaluate the function of each listed Windows service.
The Remote Registry service allows remote users to edit registry settings over the network. Disabling it prevents remote manipulation while retaining normal local OS operations.
Turning off unneeded network services reduces the remote attack surface.

Anahtar Kavram

Disabling Unnecessary Services and Hardening System Baselines
Bu soruyu puanla