SSCP Systems and Application Security Practice Question
A security engineer is hardening a Windows server. Which TWO actions should be taken to reduce the attack surface? (Select TWO.)
⚠ Common exam trap
SSCP often tests whether candidates recognize that adding software, accounts, or convenience features increases attack surface — the trap is picking options that sound like monitoring or auditing improvements but actually expand risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable unnecessary services and accounts
Option C is correct because disabling unnecessary services and accounts directly shrinks the attack surface by removing exploitable entry points, listening ports, and credentials that attackers could abuse for privilege escalation or lateral movement. Option D is correct because applying the latest security patches remediates known vulnerabilities (e.g., remote code execution flaws) that malware and threat actors actively exploit, which is a foundational hardening step. Option A is wrong because creating more active user accounts expands the attack surface and increases credential-management risk rather than reducing it. Option B is wrong because enabling AutoRun for removable media facilitates malware propagation via USB drives and should typically be disabled. Option E is wrong because installing additional third-party software adds new code, services, and potential vulnerabilities, enlarging rather than reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the number of active user accounts for auditing
Why it's wrong here
Creating more active user accounts multiplies credentials, privileges and possible entry points, enlarging the attack surface instead of shrinking it. It is tempting because auditing seems security-related, but hardening demands least privilege and disabling unused accounts; auditing is achieved through logging, not extra accounts.
- ✗
Enable auto-run for removable media to improve user convenience
Why it's wrong here
Auto-run executes code from removable media automatically, letting infected USB devices launch malware without user action and expanding the attack surface. It is tempting because it improves convenience, but hardening requires disabling AutoRun and AutoPlay; convenience is deliberately sacrificed for security.
- ✓
Disable unnecessary services and accounts
Why this is correct
Disabling unnecessary services and accounts removes unused listening ports and dormant credentials, directly shrinking exploitable entry points. This satisfies the hardening requirement by eliminating attack vectors that patching alone cannot address, since unused services still expose the Windows server.
- ✓
Apply the latest security patches
Why this is correct
Applying current security patches removes known exploitable vulnerabilities in Windows components and services, directly shrinking the attack surface. This satisfies the hardening requirement by eliminating published flaws attackers routinely leverage, complementing service and account reduction.
- ✗
Install additional third-party software for monitoring
Why it's wrong here
Adding third-party monitoring software introduces new code, services and potential vulnerabilities, enlarging rather than reducing the attack surface. It is tempting because monitoring aids detection, but hardening means removing unnecessary roles, services and features; monitoring belongs to a separate detective-control objective.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.