easyMultiple Choice
CAS-004 Practice Question: Wants to reduce the attack surface of its web…
An organization wants to reduce the attack surface of its web servers by ensuring only necessary modules are enabled. Which practice directly supports this goal?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application whitelisting and module disablement
Application whitelisting and module disablement. This practice directly reduces the attack surface by ensuring only authorized applications and necessary modules are enabled, eliminating unnecessary services that could be exploited. Option A (Patch management) addresses vulnerabilities in existing software but does not remove unused modules. Option C (Regular backups) focuses on data recovery, not attack surface reduction. Option D (Multi-factor authentication) strengthens access control but does not limit enabled modules or applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch management
Why it's wrong here
Patch management remediates known vulnerabilities in installed code; it does not remove or disable unused modules, so the exposed attack surface stays the same. It would be the right control for closing published CVEs on components you must keep running, whereas module hardening requires disabling unneeded features.
- ✓
Application whitelisting and module disablement
Why this is correct
Disabling unused modules directly shrinks the web server's exploitable surface, satisfying the stem's requirement that only necessary modules stay enabled. Application whitelisting complements this by blocking unapproved executables, preventing attackers from loading rogue modules or code onto the hardened host.
- ✗
Regular backups
Why it's wrong here
Regular backups provide recoverability after data loss or compromise; they leave every enabled module listening and exploitable, so the attack surface is unchanged. Backups would be the right control for restoring service following ransomware or corruption, not for reducing the number of exposed services on a web server.
- ✗
Multi-factor authentication
Why it's wrong here
MFA hardens authentication by requiring a second factor; it does not touch which server modules are loaded, so the web server's attack surface stays unchanged. It is tempting because MFA genuinely reduces credential-theft risk, and would be the right control when the requirement is protecting account logins rather than trimming enabled modules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.