Courseiva

SSCP Systems and Application Security Practice Question

An organization is hardening a Linux server. Which TWO of the following are effective steps to reduce the attack surface?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove unnecessary services and software packages

Removing unnecessary services and software reduces potential vulnerabilities. Proper file permissions using chmod and chown enforce least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable SELinux for better performance

    Why it's wrong here

    Disabling SELinux strips mandatory access control, letting a compromised process reach files and services beyond its policy, so it should stay enforcing. It is tempting because troubleshooting denials is faster with SELinux permissive or off, and that shortcut is defensible only on isolated lab systems.

  • ✗

    Install all available packages to ensure compatibility

    Why it's wrong here

    Installing every available package adds unnecessary daemons, libraries and services, each carrying its own vulnerabilities, so only required software should be present. It is tempting because broad package installation is a quick way to guarantee dependency compatibility on development or build machines where convenience outweighs exposure.

  • ✓

    Remove unnecessary services and software packages

    Why this is correct

    Removing unnecessary services and packages eliminates unused daemons, open ports and vulnerable libraries, shrinking the number of exploitable entry points on the host. This directly reduces the attack surface, which is the hardening goal stated in the scenario.

  • ✓

    Set file permissions using chmod and chown to restrict access

    Why this is correct

    Applying chmod and chown enforces least privilege at the filesystem layer, so only authorised users and groups can read, write or execute sensitive files. This directly reduces the attack surface by removing world-readable and world-writable permissions that attackers exploit.

  • ✗

    Enable the root account for direct login

    Why it's wrong here

    Direct root login removes accountability and gives attackers a known, privileged account to target, so administrators should use sudo from named accounts instead. It is tempting because root access is sometimes enabled for convenience during initial provisioning or break-glass recovery, where no alternative administrative path exists.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.