Courseiva
Security Operations →mediumMultiple Select

ISC2 CC Security Operations Practice Question

A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)

⚠ Common exam trap

The trap here is equating any security control, such as encryption or backups, with attack-surface reduction, when only removing exposed functionality and limiting privileges actually shrink what an attacker can target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce least privilege by removing unnecessary administrative rights and using dedicated service accounts with minimal permissions.

Reducing the operating system's attack surface means removing or disabling anything not required for the server's role and limiting the privileges available to users and services. Eliminating unnecessary daemons and ports removes entry points, while least privilege and dedicated service accounts constrain what an attacker can do if one is reached. Encryption, alert-only intrusion prevention, and backups address confidentiality, detection, or recovery rather than shrinking the exploitable surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install a host-based intrusion prevention system and configure it to alert only.

    Why it's wrong here

    A host-based intrusion prevention system in alert-only mode detects and logs suspicious activity but does not block it, so it does not reduce the attack surface. It adds visibility rather than removing exposure. To affect the attack surface it would need prevention enabled and tuned, and even then it complements rather than replaces service reduction and least privilege.

  • ✗

    Enable full-disk encryption on the server's data volumes.

    Why it's wrong here

    Full-disk encryption protects data at rest if the physical disk is stolen, but it does not reduce the number of exposed services or the operating system's exploitable surface while the server is running. It addresses confidentiality of stored data rather than the attack surface presented to the network. It is a valuable control but not a host attack-surface reduction.

  • ✓

    Enforce least privilege by removing unnecessary administrative rights and using dedicated service accounts with minimal permissions.

    Why this is correct

    Limiting administrative rights and running services under dedicated low-privilege accounts constrains what an attacker can do after gaining a foothold. It reduces the number of accounts and processes capable of modifying the system or escalating privileges. This directly shrinks the exploitable surface and limits blast radius, making it a core hardening practice.

  • ✓

    Remove or disable unnecessary services, daemons, and open ports that are not required for the server's role.

    Why this is correct

    Every listening service is a potential entry point, so removing or disabling unneeded daemons and closing unused ports directly shrinks the attack surface. This aligns with the principle of least functionality and reduces the number of vulnerabilities an attacker can target. It is a foundational host-hardening step that applies before any application is deployed.

  • ✗

    Schedule weekly full backups of the server to a remote location.

    Why it's wrong here

    Backups improve recovery after an incident but do not reduce the number of services, ports, or privileged accounts an attacker can exploit. They are a resilience control, not a preventive hardening measure. Relying on backups alone leaves the same attack surface exposed and does nothing to stop initial compromise.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.