hardMultiple Select
ISC2 CC Practice Question: Which THREE of the following are essential…
Which THREE of the following are essential components of a security baseline configuration for a server?
⚠ Common exam trap
ISC2 often tests the principle of least functionality by making candidates think that installing all optional software ensures compatibility, when in reality it violates the core security baseline goal of reducing the attack surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable unnecessary services.
A security baseline configuration for a server must minimize the attack surface, so option A (Disable unnecessary services) is correct because every running service is a potential entry point and removing unneeded ones reduces exploitable ports and daemons. Option B (Enable auditing and logging) is correct because it provides the visibility needed to detect, investigate, and respond to security events, and is a standard hardening requirement in frameworks like CIS Benchmarks and NIST SP 800-123. Option C (Apply the latest security patches) is correct because unpatched software is a primary vector for exploitation, and timely patching of the OS and applications is a foundational baseline control. Option D (Install all optional software for functionality) is not part of a security baseline because installing unnecessary software expands the attack surface and contradicts the principle of least functionality. Option E (Grant administrative rights to all users) is not part of a security baseline because it violates least privilege and dramatically increases the risk of privilege abuse and compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable unnecessary services.
Why this is correct
Disabling unnecessary services shrinks the attack surface by removing listening daemons and their associated vulnerabilities, directly satisfying the baseline requirement to eliminate non-essential functionality. Each disabled service removes potential entry points that attackers could exploit, ensuring only required roles run on the server.
- ✓
Enable auditing and logging.
Why this is correct
Auditing and logging provide the forensic evidence trail required to detect policy violations and confirm whether other baseline controls remain intact. Without recorded events, you cannot verify compliance or investigate incidents, so logging satisfies the stem's demand for an essential baseline component alongside patching and access hardening.
- ✓
Apply the latest security patches.
Why this is correct
Applying current security patches closes known vulnerabilities that attackers actively exploit, directly satisfying the baseline's requirement to harden servers against published threats. Patching is an essential, ongoing control because unpatched systems remain exposed regardless of other settings. It addresses the stem's demand for essential baseline components by removing exploitable weaknesses before they can be leveraged.
- ✗
Install all optional software for functionality.
Why it's wrong here
Optional software enlarges the attack surface, so a hardened baseline removes or disables unnecessary packages rather than installing them. It is tempting because extra functionality can appear useful, and installing optional components is legitimate when a documented business requirement demands that specific capability.
- ✗
Grant administrative rights to all users.
Why it's wrong here
Granting administrative rights to all users violates least privilege, letting any compromised account alter system configuration. It is tempting because broad admin rights remove permission friction during troubleshooting, and that approach is defensible only in isolated, disposable lab environments with no sensitive data.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Security baseline
A security baseline is a documented minimum set of security configurations and settings that must be applied to a system, device, or network to ensure a known secure starting point.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.