
Introduction to Minimizing the Attack Surface
Authored by Mary Velasco
Computers
12th Grade
Used 3+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
10 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which statement best defines the security principle of minimizing the attack surface?
Adding more services to improve redundancy and performance
Reducing the number of potential entry points or vulnerabilities attackers can exploit
Allowing broader access to increase usability for all users
Encrypting all data at rest without changing system configuration
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
According to the material, which actions directly help reduce the number of ways an attacker can exploit a system?
Enabling all optional services by default
Minimizing running services, open ports, and exposed code base
Sharing administrator credentials to simplify support
Disabling network segmentation
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which action best aligns with the Principle of Least Privilege to minimize the attack surface?
Allow all users administrator rights for convenience
Grant users only the minimum access needed to perform their functions
Disable all services, including essential ones
Install additional optional modules to expand functionality
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which action best exemplifies network segmentation to limit the potential impact of a breach?
Placing applications in containers or virtual machines
Configuring a firewall to block all outgoing traffic
Dividing the network into isolated parts based on function or trust level
Enabling remote access to all internal services
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A company wants to reduce exposure of internal services while allowing remote employees to connect securely. Which approach aligns with the guidance?
Expose all services directly to the internet for convenience
Use VPNs or other secure methods for remote access and limit service exposure
Rely only on strong passwords without network controls
Disable the firewall to prevent conflicts
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which security tool is specifically used to identify and address potential security weaknesses in a system?
Intrusion Detection/Prevention Systems (IDS/IPS)
Vulnerability Scanners
Firewall Rules
Encryption Algorithms
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which statement best explains how minimizing the attack surface supports regulatory compliance?
It eliminates the need for any security controls.
It helps meet regulatory and industry standards that require robust security practices and improves audit readiness.
It guarantees that no security incidents will occur.
It primarily focuses on reducing software licensing fees.
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?