FC0-U71 Security Practice Question
An IT administrator is hardening a server. Which three of the following actions should be taken to improve security? (Select THREE.)
⚠ Common exam trap
FC0-U71 often tests the misconception that performance or convenience (disabling firewall, granting admin rights) improves security—candidates must recognize that these actions weaken security, while the three correct choices are standard hardening measures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable unused services and ports
Option A is correct because disabling unused services and closing unused ports reduces the attack surface, eliminating unnecessary daemons and listening sockets that attackers could exploit. Option B is correct because applying the principle of least privilege ensures users and processes receive only the minimum rights needed, limiting the blast radius of a compromise or insider misuse. Option D is correct because enabling automatic software updates ensures timely patching of known vulnerabilities in the OS and applications, closing exploits before they can be leveraged. Option C is incorrect because disabling the firewall removes a critical network access control layer and exposes services to unauthorized traffic, harming rather than improving security. Option E is incorrect because granting all users administrative rights violates least privilege and dramatically increases the risk of privilege abuse and malware propagation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable unused services and ports
Why this is correct
Disabling unused services and ports shrinks the attack surface by removing listening daemons and open sockets that attackers could exploit. This directly satisfies the hardening goal, since every unnecessary service is a potential entry point for exploitation or lateral movement.
- ✓
Implement the principle of least privilege
Why this is correct
Least privilege restricts each account, process and service to only the permissions its function requires, shrinking the exploitable attack surface if credentials are compromised. This directly satisfies the hardening goal by limiting lateral movement and privilege escalation on the server.
- ✗
Disable the firewall for better performance
Why it's wrong here
Disabling the firewall strips packet filtering, leaving every listening port reachable, which directly contradicts hardening. It is tempting because firewall inspection consumes CPU and can add latency, so it is sometimes disabled on isolated, trusted lab networks where throughput testing matters, not on an internet-facing production server.
- ✓
Enable automatic software updates
Why this is correct
Automatic updates promptly patch known vulnerabilities in the operating system and installed software, closing the exposure window attackers exploit. This directly hardens the server by removing exploitable flaws without relying on manual intervention, satisfying the hardening requirement.
- ✗
Grant all users administrative rights
Why it's wrong here
Granting every user administrative rights removes the least-privilege boundary, so any compromised account can alter system files, services and audit logs. It is tempting because administrators genuinely need elevated rights to install and configure software, but that privilege should be scoped to a small, audited group rather than the whole user base.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.