ISC2 CC Security Operations Practice Question
An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)
⚠ Common exam trap
The trap is selecting convenience features like automatic login or unrestricted RDP because they seem efficient, but hardening always prioritizes security over convenience—candidates must recognize that these are anti-patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disabling unnecessary services and ports.
Option B is correct because a hardened baseline minimizes the attack surface by disabling unnecessary services and closing unused ports, reducing the number of exploitable entry points on a new server. Option D is correct because enforcing strong password policies (for example, minimum length, complexity, and expiration requirements) strengthens authentication and mitigates brute-force and credential-guessing attacks. Option E is correct because installing all available security patches ensures known vulnerabilities in the OS and applications are remediated before the server is placed into production. Option A does not belong because allowing RDP from any IP address exposes the server to unauthorized remote access and should instead be restricted to trusted management networks. Option C does not belong because automatic login for administrators bypasses authentication entirely, directly undermining the purpose of a security baseline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allowing remote desktop access from any IP address.
Why it's wrong here
Allowing RDP from any source address contradicts a hardened baseline, which restricts management access through network-level controls such as just-in-time VM access or IP allow-listing. It is tempting because Remote Desktop remains a legitimate administrative mechanism for Windows servers; it would be acceptable only when paired with source restrictions, MFA and Microsoft Entra ID conditional access.
- ✓
Disabling unnecessary services and ports.
Why this is correct
Disabling unnecessary services and ports shrinks the attack surface by removing listening daemons and open sockets that are not required for the server's role. This is a core hardening step, directly satisfying the baseline requirement to minimise exploitable entry points on new servers.
- ✗
Enabling automatic login for administrators.
Why it's wrong here
Enabling automatic login removes the credential prompt that hardened baselines require, directly contradicting the authentication controls a security baseline enforces. It is tempting because it streamlines administrator access to servers, reducing repeated sign-in friction. Automatic login suits dedicated kiosks or lab machines where convenience outweighs risk, not production servers governed by a hardening baseline.
- ✓
Enforcing strong password policies.
Why this is correct
Strong password policies enforce complexity, length and rotation requirements at the account level, blocking credential-guessing and brute-force attacks against new servers. This is a standard hardening control, directly satisfying the baseline requirement to restrict authentication weaknesses before deployment.
- ✓
Installing all available security patches.
Why this is correct
Installing all available security patches is a fundamental component of a hardened baseline configuration for new servers. This practise ensures that systems are immediately protected against known vulnerabilities and exploits that have been identified and addressed by software vendors. By applying these updates from the outset, the organisation establishes a robust security posture, significantly reducing the attack surface and satisfying the requirement for a secure, resilient foundation before deployment.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Baseline
A baseline is a documented starting point for the normal performance and behavior of a system, network, or component, used to detect changes and troubleshoot issues.
Key term
Baseline configuration
A baseline configuration is a documented set of specifications for hardware, software, and settings that serves as a consistent starting point for systems in an IT environment.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.