An IT security team is establishing baseline endpoint hardening configurations for newly deployed employee workstations. Which TWO of the following technical measures directly reduce the local host attack surface?
- Disabling unnecessary operating system services and unneeded network protocolsCevap
- BDeploying inline honeypot servers at the network edge to filter inbound workstation traffic
- Removing default user accounts and enforcing least privilege for local administrator permissionsCevap
- DRelying on perimeter firewall rules to inspect and control local workstation process execution
Cevap
The correct measures are disabling unnecessary operating system services/protocols and removing default accounts while enforcing least privilege on local administrator permissions.
Host hardening involves applying configurations that decrease systemic vulnerability on individual endpoints. Disabling unnecessary default services and network protocols removes unused software pathways that attackers could exploit. Concurrently, removing default accounts and restricting local administrative privileges ensures that even if a user or system is compromised, execution rights are heavily constrained.
Adım Adım Çözüm
Anahtar Kavram
Host Hardening and Attack Surface Reduction