Courseiva
hardMultiple Select

ISC2 CC Practice Question: Which THREE of the following are essential…

Which THREE of the following are essential components of a security baseline configuration for a server?

⚠ Common exam trap

ISC2 often tests the principle of least functionality by making candidates think that installing all optional software ensures compatibility, when in reality it violates the core security baseline goal of reducing the attack surface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable unnecessary services.

A security baseline configuration for a server must minimize the attack surface, so option A (Disable unnecessary services) is correct because every running service is a potential entry point and removing unneeded ones reduces exploitable ports and daemons. Option B (Enable auditing and logging) is correct because it provides the visibility needed to detect, investigate, and respond to security events, and is a standard hardening requirement in frameworks like CIS Benchmarks and NIST SP 800-123. Option C (Apply the latest security patches) is correct because unpatched software is a primary vector for exploitation, and timely patching of the OS and applications is a foundational baseline control. Option D (Install all optional software for functionality) is not part of a security baseline because installing unnecessary software expands the attack surface and contradicts the principle of least functionality. Option E (Grant administrative rights to all users) is not part of a security baseline because it violates least privilege and dramatically increases the risk of privilege abuse and compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable unnecessary services.

    Why this is correct

    Disabling unnecessary services shrinks the attack surface by removing listening daemons and their associated vulnerabilities, directly satisfying the baseline requirement to eliminate non-essential functionality. Each disabled service removes potential entry points that attackers could exploit, ensuring only required roles run on the server.

  • ✓

    Enable auditing and logging.

    Why this is correct

    Auditing and logging provide the forensic evidence trail required to detect policy violations and confirm whether other baseline controls remain intact. Without recorded events, you cannot verify compliance or investigate incidents, so logging satisfies the stem's demand for an essential baseline component alongside patching and access hardening.

  • ✓

    Apply the latest security patches.

    Why this is correct

    Applying current security patches closes known vulnerabilities that attackers actively exploit, directly satisfying the baseline's requirement to harden servers against published threats. Patching is an essential, ongoing control because unpatched systems remain exposed regardless of other settings. It addresses the stem's demand for essential baseline components by removing exploitable weaknesses before they can be leveraged.

  • ✗

    Install all optional software for functionality.

    Why it's wrong here

    Optional software enlarges the attack surface, so a hardened baseline removes or disables unnecessary packages rather than installing them. It is tempting because extra functionality can appear useful, and installing optional components is legitimate when a documented business requirement demands that specific capability.

  • ✗

    Grant administrative rights to all users.

    Why it's wrong here

    Granting administrative rights to all users violates least privilege, letting any compromised account alter system configuration. It is tempting because broad admin rights remove permission friction during troubleshooting, and that approach is defensible only in isolated, disposable lab environments with no sensitive data.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.