Courseiva

Host Firewall Hardening and Least Privilege for Security+

Exhibit

Server review:
- Inbound firewall policy: allow any source to any port
- Web service account: domain admin
- Required flows: load balancer to web service, jump host to admin port
- No other inbound access should be permitted

A web server should accept traffic only from a load balancer and a management jump host. The current host firewall allows all inbound ports, and the web service runs as a domain administrator. Which two changes most improve hardening without breaking the required access pattern? Select two.

Quick Answer

The answer is to restrict the host firewall to only the load balancer and management jump host, and to run the web service under a dedicated nonadministrative service account. These two changes directly enforce host firewall hardening and least privilege by limiting inbound traffic to specific source IPs and required ports while stripping unnecessary administrative rights from the service process. On the Security+ SY0-701 exam, this scenario tests your understanding of network segmentation and the principle of least privilege as applied to both access control and service accounts—a common trap is to only fix the firewall while leaving the service running with excessive privileges. Remember the memory tip: “Lock the door and drop the keys”—restrict what comes in (firewall rules) and limit what the service can do (nonadmin account).

⚠ Common exam trap

The trap here is that candidates often focus on password strength or patching schedules while ignoring the critical need for network segmentation and least-privilege service accounts, which are the foundational controls tested in this question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict host firewall rules to required source addresses and ports.

Option A is correct because narrowing the host firewall to only the load balancer's and jump host's source IP addresses on the specific service ports enforces least-privilege network access while preserving the required traffic pattern. Option B is correct because running the web service under a dedicated nonadministrative service account removes the excessive privileges of a domain administrator, limiting the blast radius if the service is compromised. Option C is wrong because leaving SSH open to every subnet and relying on passwords violates least privilege and weakens authentication. Option D is wrong because granting local administrator rights to the service account expands privileges rather than hardening. Option E is wrong because permanently disabling patching leaves known vulnerabilities unaddressed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Restrict host firewall rules to required source addresses and ports.

    Why this is correct

    Restricting firewall rules to the load balancer's and jump host's source addresses, on only the ports the web service needs, enforces least privilege at the network layer. This satisfies the stem's constraint of preserving the required access pattern while eliminating all other inbound traffic, directly hardening the host.

  • ✓

    Run the service under a dedicated nonadministrative service account.

    Why this is correct

    Running the web service under a dedicated nonadministrative service account removes the domain administrator's excessive privileges, satisfying least-privilege hardening. If the service is compromised, the attacker inherits only the service account's limited rights rather than domain-wide administrative control, containing lateral movement without affecting the load balancer or jump host access pattern.

  • ✗

    Leave SSH open to every subnet and rely on strong passwords.

    Why it's wrong here

    Leaving SSH open to every subnet exposes the management plane far beyond the jump host, and passwords alone do not satisfy the required access pattern. Strong passwords are relevant where key-based authentication is unavailable, but here the firewall should restrict SSH to the jump host's address.

  • ✗

    Give the service account local administrator rights so it can restart itself.

    Why it's wrong here

    Granting local administrator rights widens the blast radius if the web service is compromised, directly contradicting least privilege. It is tempting because services sometimes need to restart themselves, but that is handled through service recovery settings or scoped permissions, not full administrative rights.

  • ✗

    Disable patching during business hours permanently.

    Why it's wrong here

    Patching must continue; disabling it permanently leaves known vulnerabilities unpatched, directly undermining hardening. It is tempting because deferring patches avoids disruptive reboots during peak traffic, and a controlled maintenance window would be the correct approach for managing patch-related downtime.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During an incident, a server administrator needs elevated access to production logs for exactly two hours after manager approval. The organization does not want standing privileged accounts. Which solution is the best fit?

medium
  • A.Add the administrator to a permanent domain admin group so access is always available.
  • ✓ B.Use just-in-time privileged access through a privileged access management workflow.
  • C.Create a shared administrator account for the incident team and change the password afterward.
  • D.Grant access by sending the administrator a VPN profile with broader network reach.

Why B: Just-in-time (JIT) privileged access through a Privileged Access Management (PAM) workflow is the best fit because it grants the administrator elevated permissions for exactly two hours, then automatically revokes them. This aligns with the requirement for time-limited access without maintaining standing privileged accounts, reducing the attack surface and ensuring compliance with the principle of least privilege.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.