SSCP Systems and Application Security Practice Question
A security engineer is hardening a Windows server that hosts a critical database. The server currently has many unnecessary services running. Which TWO of the following actions are most effective in reducing the attack surface of this server? (Choose two.)
⚠ Common exam trap
Candidates often confuse general security best practices like antivirus or least privilege with specific attack surface reduction techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a host-based firewall and close unused ports.
Reducing attack surface involves eliminating unnecessary functionality and restricting access. Disabling unused services and features removes potential vulnerabilities, while closing unused ports and enabling a host-based firewall limits network exposure. Together, these actions significantly shrink the opportunities for an attacker to exploit the server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement full disk encryption on the server's drives.
Why it's wrong here
Full disk encryption protects data at rest if the physical drive is stolen, but it does not reduce the attack surface of a running server. The attack surface is about accessible services and code, not data confidentiality. This is a data protection control, not attack surface reduction.
- ✗
Apply the principle of least privilege to user accounts.
Why it's wrong here
Least privilege limits the damage from a compromised account but does not reduce the attack surface of the server itself. The attack surface is about the code and services exposed, not user permissions. This is a valuable practice but not the primary action to reduce attack surface.
- ✗
Install the latest antivirus software and keep it updated.
Why it's wrong here
Antivirus is a detective and reactive control, not a proactive reduction of attack surface. While important, it does not remove unnecessary services or features that could be exploited. The question asks for reducing attack surface, which is about minimizing exposed functionality.
- ✓
Enable a host-based firewall and close unused ports.
Why this is correct
Closing unused ports and enabling a host-based firewall restricts network access to only necessary services, directly reducing the attack surface. This prevents attackers from reaching potentially vulnerable services. It is a key hardening measure for servers.
- ✓
Disable unused Windows services and features.
Why this is correct
Disabling unused services and features eliminates potential entry points and reduces the number of vulnerabilities that can be exploited. This directly shrinks the attack surface by removing unnecessary code from running. It is a fundamental hardening step for any server.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.