Host Firewall Hardening and Least Privilege for Security+
Exhibit
Server review: - Inbound firewall policy: allow any source to any port - Web service account: domain admin - Required flows: load balancer to web service, jump host to admin port - No other inbound access should be permitted
A web server should accept traffic only from a load balancer and a management jump host. The current host firewall allows all inbound ports, and the web service runs as a domain administrator. Which two changes most improve hardening without breaking the required access pattern? Select two.
Quick Answer
The answer is to restrict the host firewall to only the load balancer and management jump host, and to run the web service under a dedicated nonadministrative service account. These two changes directly enforce host firewall hardening and least privilege by limiting inbound traffic to specific source IPs and required ports while stripping unnecessary administrative rights from the service process. On the Security+ SY0-701 exam, this scenario tests your understanding of network segmentation and the principle of least privilege as applied to both access control and service accounts—a common trap is to only fix the firewall while leaving the service running with excessive privileges. Remember the memory tip: “Lock the door and drop the keys”—restrict what comes in (firewall rules) and limit what the service can do (nonadmin account).
⚠ Common exam trap
The trap here is that candidates often focus on password strength or patching schedules while ignoring the critical need for network segmentation and least-privilege service accounts, which are the foundational controls tested in this question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict host firewall rules to required source addresses and ports.
Option A is correct because narrowing the host firewall to only the load balancer's and jump host's source IP addresses on the specific service ports enforces least-privilege network access while preserving the required traffic pattern. Option B is correct because running the web service under a dedicated nonadministrative service account removes the excessive privileges of a domain administrator, limiting the blast radius if the service is compromised. Option C is wrong because leaving SSH open to every subnet and relying on passwords violates least privilege and weakens authentication. Option D is wrong because granting local administrator rights to the service account expands privileges rather than hardening. Option E is wrong because permanently disabling patching leaves known vulnerabilities unaddressed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict host firewall rules to required source addresses and ports.
Why this is correct
Restricting firewall rules to the load balancer's and jump host's source addresses, on only the ports the web service needs, enforces least privilege at the network layer. This satisfies the stem's constraint of preserving the required access pattern while eliminating all other inbound traffic, directly hardening the host.
- ✓
Run the service under a dedicated nonadministrative service account.
Why this is correct
Running the web service under a dedicated nonadministrative service account removes the domain administrator's excessive privileges, satisfying least-privilege hardening. If the service is compromised, the attacker inherits only the service account's limited rights rather than domain-wide administrative control, containing lateral movement without affecting the load balancer or jump host access pattern.
- ✗
Leave SSH open to every subnet and rely on strong passwords.
Why it's wrong here
Leaving SSH open to every subnet exposes the management plane far beyond the jump host, and passwords alone do not satisfy the required access pattern. Strong passwords are relevant where key-based authentication is unavailable, but here the firewall should restrict SSH to the jump host's address.
- ✗
Give the service account local administrator rights so it can restart itself.
Why it's wrong here
Granting local administrator rights widens the blast radius if the web service is compromised, directly contradicting least privilege. It is tempting because services sometimes need to restart themselves, but that is handled through service recovery settings or scoped permissions, not full administrative rights.
- ✗
Disable patching during business hours permanently.
Why it's wrong here
Patching must continue; disabling it permanently leaves known vulnerabilities unpatched, directly undermining hardening. It is tempting because deferring patches avoids disruptive reboots during peak traffic, and a controlled maintenance window would be the correct approach for managing patch-related downtime.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Certificate Lifecycle Management
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During an incident, a server administrator needs elevated access to production logs for exactly two hours after manager approval. The organization does not want standing privileged accounts. Which solution is the best fit?
medium- A.Add the administrator to a permanent domain admin group so access is always available.
- ✓ B.Use just-in-time privileged access through a privileged access management workflow.
- C.Create a shared administrator account for the incident team and change the password afterward.
- D.Grant access by sending the administrator a VPN profile with broader network reach.
Why B: Just-in-time (JIT) privileged access through a Privileged Access Management (PAM) workflow is the best fit because it grants the administrator elevated permissions for exactly two hours, then automatically revokes them. This aligns with the requirement for time-limited access without maintaining standing privileged accounts, reducing the attack surface and ensuring compliance with the principle of least privilege.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.