SSCP Systems and Application Security Practice Question
During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?
⚠ Common exam trap
SSCP often tests whether candidates choose compensating or detective controls (segmentation, HIDS) over direct remediation — the trap is overlooking that the question asks for the most effective hardening action against the specific findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable Telnet and FTP services, and apply all critical security patches.
The most effective hardening approach directly addresses the identified vulnerabilities: disabling insecure services (Telnet and FTP, which transmit credentials in cleartext) and applying critical security patches to close known exploitable flaws. This removes the actual attack vectors rather than merely monitoring or isolating them, aligning with CIS and NIST hardening guidance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the server to a more secure network segment and implement network access controls.
Why it's wrong here
Segmentation and network access controls limit reachability but leave Telnet, FTP and unpatched software running on the host, so the vulnerabilities persist. This approach suits containing a compromised or legacy system, not hardening the server itself, which requires disabling services and applying patches.
- ✗
Enable SELinux and configure a host-based firewall using iptables.
Why it's wrong here
SELinux and iptables restrict access and filter traffic, but Telnet and FTP remain installed and listening, and the missing patches stay unapplied. These controls suit limiting lateral movement or enforcing least privilege, yet they do not satisfy the stem's requirement to eliminate unnecessary services and remediate patch gaps.
- ✗
Install a host-based intrusion detection system (HIDS) to monitor for attacks.
Why it's wrong here
A HIDS only detects and alerts on malicious activity after it occurs; it neither removes Telnet and FTP nor applies missing patches, leaving the actual exposures open. Monitoring suits environments where detection of ongoing compromise is the goal, but hardening here demands disabling unnecessary services and patching.
- ✓
Disable Telnet and FTP services, and apply all critical security patches.
Why this is correct
Disabling Telnet and FTP removes insecure cleartext protocols, while patching closes known vulnerabilities. Together they eliminate both the exposed attack surface and the exploitable flaws, satisfying the hardening requirement more completely than either measure alone.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?
easy- A.Configure a host-based firewall to allow Telnet only from specific IPs
- B.Enable encryption on Telnet
- ✓ C.Remove the Telnet service and use SSH instead
- D.Audit Telnet connections in Event Viewer
Why C: The best action is to remove Telnet and use SSH instead because Telnet transmits data, including credentials, in cleartext, making it inherently insecure. SSH provides encrypted communication, eliminating the vulnerability. Removing the service also reduces the attack surface.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.