Courseiva
Security →hardMultiple Select

FC0-U71 Security Practice Question

An IT administrator is hardening a server. Which three of the following actions should be taken to improve security? (Select THREE.)

⚠ Common exam trap

FC0-U71 often tests the misconception that performance or convenience (disabling firewall, granting admin rights) improves security—candidates must recognize that these actions weaken security, while the three correct choices are standard hardening measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable unused services and ports

Option A is correct because disabling unused services and closing unused ports reduces the attack surface, eliminating unnecessary daemons and listening sockets that attackers could exploit. Option B is correct because applying the principle of least privilege ensures users and processes receive only the minimum rights needed, limiting the blast radius of a compromise or insider misuse. Option D is correct because enabling automatic software updates ensures timely patching of known vulnerabilities in the OS and applications, closing exploits before they can be leveraged. Option C is incorrect because disabling the firewall removes a critical network access control layer and exposes services to unauthorized traffic, harming rather than improving security. Option E is incorrect because granting all users administrative rights violates least privilege and dramatically increases the risk of privilege abuse and malware propagation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable unused services and ports

    Why this is correct

    Disabling unused services and ports shrinks the attack surface by removing listening daemons and open sockets that attackers could exploit. This directly satisfies the hardening goal, since every unnecessary service is a potential entry point for exploitation or lateral movement.

  • ✓

    Implement the principle of least privilege

    Why this is correct

    Least privilege restricts each account, process and service to only the permissions its function requires, shrinking the exploitable attack surface if credentials are compromised. This directly satisfies the hardening goal by limiting lateral movement and privilege escalation on the server.

  • ✗

    Disable the firewall for better performance

    Why it's wrong here

    Disabling the firewall strips packet filtering, leaving every listening port reachable, which directly contradicts hardening. It is tempting because firewall inspection consumes CPU and can add latency, so it is sometimes disabled on isolated, trusted lab networks where throughput testing matters, not on an internet-facing production server.

  • ✓

    Enable automatic software updates

    Why this is correct

    Automatic updates promptly patch known vulnerabilities in the operating system and installed software, closing the exposure window attackers exploit. This directly hardens the server by removing exploitable flaws without relying on manual intervention, satisfying the hardening requirement.

  • ✗

    Grant all users administrative rights

    Why it's wrong here

    Granting every user administrative rights removes the least-privilege boundary, so any compromised account can alter system files, services and audit logs. It is tempting because administrators genuinely need elevated rights to install and configure software, but that privilege should be scoped to a small, audited group rather than the whole user base.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.