NEW
Font size
WorksheetsIntroduction to Server Security
Total questions: 60
Worksheet time: 30mins
Which characteristic most distinguishes servers from clients in enterprise environments?
Hosting essential business services
Used mainly by individual users
Operate with lower privilege levels
Limited exposure to network threats
Why are servers considered high-value targets for cyber attackers?
They are rarely connected to the internet
They run only during business hours
They have fewer network interfaces
They store critical services and data
What does 24/7 availability imply for server security risk?
Reduced need for authentication
Fewer maintenance windows
Continuous attack opportunities
Guaranteed uptime for clients
Which statement best describes multiple network connections on servers?
Eliminate need for firewalls entirely
Limit interface types to one protocol
Reduce exposure to external threats
Increase functionality and entry points
Which attribute is typical of client systems compared to servers?
Require constant uptime
Host authentication services
Primarily for individual users
Expose many network entry points
Compromise of a server is more severe mainly because servers are essential to what?
Personal entertainment
Business continuity
Single user preferences
Local file printing
Which scenario best illustrates exploiting unpatched vulnerabilities on a server?
Outdated software without patches
Latest firmware installed promptly
Strong passwords rotated weekly
Ports closed and filtered carefully
An attacker uses automated tools to guess RDP or SSH credentials repeatedly. What attack method is this?
Man-in-the-middle snooping
SQL injection on databases
Phishing privileged users
Brute-forcing remote access
Which configuration issue most likely leaves a server open to unauthorized access?
Misconfigured ports or services
Encrypted tunnels for backups
Multi-factor authentication enabled
Role-based access enforced
Which scenario best describes a privilege escalation attack on a server?
A guest logs out after finishing a session
A backup job runs with limited permissions
A user gains admin rights through weak settings
A service denies access to normal users
What is a common impact of ransomware targeting file shares?
Weak passwords allow faster remote logins
Deleted logs improve system performance temporarily
Encrypted files disrupt operations until payment
Open ports increase bandwidth for downloads
Attackers exfiltrate data from exposed databases primarily when the database is
Disconnected and air-gapped permanently
Improperly secured or publicly accessible
Encrypted with strong keys at all times
Hosted only on local personal devices
Which remote access services are commonly brute-forced by attackers?
RDP and SSH for remote control
NTP and SNMP for time checks
FTP and SMTP for email routing
DNS and DHCP for name resolution
A misconfigured server allows an attacker to gain higher-level access. Which preventive approach directly addresses this risk?
Frequent user interface redesign projects
Adding more decorative themes to consoles
Secure configuration baselines applied consistently
Increasing screen brightness for visibility
An organisation wants to reduce the chance of attackers moving deeper after a breach. Which combined strategy is most effective?
Daily social media updates from admins
Longer coffee breaks for IT staff
Patch management, hardening, and secure baselines
Purchasing more office printers quickly
Which description best defines patch management in an IT environment?
Process of acquiring, testing, and installing updates
Method of replacing entire systems during outages
Policy of disabling unused services for performance
Routine of backing up data before monthly maintenance
Which option correctly distinguishes security patches from bug fixes?
Security patches address vulnerabilities exploited by attackers
Bug fixes prevent social engineering through staff training
Security patches improve UI responsiveness and features
Bug fixes add new capabilities to operating systems
A company delays applying a widely available security patch for an SMB exploit. Which outcome is most likely?
Known exploits remain open and attacks can scale
Server storage increases and backups complete faster
User authentication becomes impossible across domains
Network bandwidth usage drops under normal load
In the WannaCry case, what critical lesson should IT teams learn about patch timelines?
Patches may exist months before attacks occur
Vendors rarely release patches for major exploits
Attacks only follow immediately after disclosure
Ransomware never targets legacy network protocols
During the Identify step of the patch management lifecycle, which action is most appropriate?
Subscribe to vendor alerts and inventory software
Disable automatic updates on production servers
Prioritize UI enhancements over security updates
Wait for quarterly audits to discover new patches
Which step focuses on evaluating relevance and severity to prioritize patches?
Identify vulnerabilities and affected assets
Monitor metrics and user feedback post-patch
Deploy patches during maintenance windows
Assess relevance and severity for prioritization
What is the primary purpose of testing patches in a controlled environment?
To speed up production deployment timelines
To ensure no new issues or conflicts appear
To document long-term performance impacts
To confirm user acceptance and feedback loops
During deployment, what practice minimizes disruption?
Immediate rollout to all endpoints
Unscheduled overnight deployments
Scheduled maintenance window deployment
Deploy only to least critical systems
Why should a rollback plan accompany deployment?
To meet vendor licensing requirements
To revert if unforeseen issues occur
To accelerate patch installation speed
To avoid the need for testing
Which activity confirms that all intended fixes are operational after patching?
Regression testing in staging
Verification through logs and acceptance
Prioritization based on severity
Continuous monitoring of metrics
What ongoing action helps identify long‑term effects of a patch?
One‑time verification checklist
Immediate production deployment
Continuous monitoring and feedback
Single round of functional testing
Which statement best reflects safe deployment guidance shown?
Deploy straight to production without tests
Roll back first, then deploy patches
Only test for performance, skip functionality
Never deploy to production without testing
A patch addresses a critical vulnerability on a payment server. Which step determines how quickly it should be applied?
Verify logs after deployment
Identify assets and patch sources
Assess severity and system criticality
Test with performance benchmarks
You completed functional and regression tests. What should happen next in the lifecycle?
Document verification outcomes
Monitor metrics for anomalies
Deploy to production with rollback
Assess again before planning
Which set of tests is recommended before production rollout?
Backup restore and disaster drills
Penetration and social engineering
Functional, regression, performance
Usability and accessibility testing
After deployment, users report slower response times. Which step addresses this issue?
Assessment of severity
Testing in isolation
Verification of fixes
Monitoring and feedback
What evidence would most strongly support that a patch succeeded in fixing an error?
Deployment occurred during maintenance
No anomalies in long‑term metrics
User feedback is generally positive
Targeted log entries show resolved faults
Which statement best defines hardening in the context of servers?
Allowing more public access to increase usability
Restricting attack paths by securing configurations
Expanding services to improve user features
Making servers faster through hardware upgrades
What is an attack surface?
All ways an attacker can interact with the system
Only the open network ports on a server
Only the services running with admin rights
Just the public website and login page
Which action most directly reduces the attack surface?
Changing server hardware to newer models
Enabling all optional services for flexibility
Disabling unnecessary services and unused ports
Increasing the number of admin accounts
Why is applying the latest security patches important?
It improves graphics performance for users
It protects against known vulnerabilities and exploits
It guarantees zero downtime for the server
It replaces the need for access controls entirely
A server is used only as a database and has pre‑installed email and web services. What should the admin do first to harden the server?
Stop and disable the unnecessary web and email services
Change hardware to increase processing speed
Create additional admin accounts for redundancy
Open more ports to improve throughput
Which ports should typically NOT be changed on a public web server?
SSH and RDP remote management ports
File transfer ports used by backups
Database service internal communication ports
HTTP and HTTPS website access ports
What is a practical risk of leaving default credentials enabled on a server?
Network latency will increase for all clients
CPU usage will spike under normal workloads
Automated attacks can easily gain unauthorized access
Users will lose access to their files
Which step adds an additional layer of protection by reducing common scans, but does not replace other measures?
Installing more third‑party applications
Allowing anonymous administrative access
Changing default service ports like SSH or RDP
Enabling every pre‑installed service
An internal application is installed but never used and exposes a listening port. What is the best hardening action?
Remove the application and close its port
Restrict internet access to the network
Keep it installed for future needs
Create a new user account for the app
Which benefit does configuring host firewall rules primarily provide on a server?
Automatically patches operating system vulnerabilities
Encrypts all data stored on the server
Ensures only authorized connections are allowed
Blocks all outbound traffic by default
Which practice best strengthens admin account security?
Share one admin password across teams
Require complex, regularly updated passwords
Use memorable dictionary words
Disable password expiration policies
What is the main goal of restricting remote access to RDP/SSH?
Reduce hardware costs for servers
Lower CPU usage during peak hours
Decrease risk of unauthorized access
Improve website loading performance
Which action aligns with the least privilege principle for services?
Use default permissions for every account
Allow temporary unrestricted access
Assign only permissions needed for tasks
Grant full admin rights to all services
Why should unused applications be removed from a server?
They can create unpatched vulnerabilities
They guarantee faster login times
They improve network throughput
They increase storage capacity
Which statement about logging and auditing is most accurate?
They replace firewall configurations
They make passwords unnecessary
They help detect and respond to incidents
They eliminate all cyber threats
Which approach best manages who has server admin rights?
Rotate admin rights randomly weekly
Set permanent admin rights for interns
Limit access to a trusted small group
Grant admin access to all developers
Which protocol should be disabled to avoid insecure remote command-line access?
SFTP, protecting file transfers safely
HTTPS, securing web traffic end-to-end
SSH, using strong encryption by default
Telnet, using plaintext authentication
Which statement explains the importance of service minimization?
Each open port can be an attack entry point
Open ports consume extra disk space
Closed ports slow down network traffic
Fewer services reduce encryption overhead
Which action is recommended for remote access security on servers?
Allow RDP from any public IP
Permit SSH without key authentication
Disable multi-factor authentication (MFA)
Restrict access to trusted IP addresses
Which service and version is flagged as risky and should be disabled?
SMBv3, modern secure alternative
SMBv1, outdated file sharing protocol
NTPv4, time synchronization service
DNSSEC, secure name resolution add-on
Which password policy element is explicitly recommended for admin accounts?
Numbers only with six characters
Avoid complex characters for usability
Mix of uppercase, lowercase, numbers, special characters
Reuse old passwords every six months
Which statement best describes a security configuration baseline for servers?
A temporary checklist for one-time installation tasks
A benchmark of recommended secure settings applied consistently
A minimum set of default open services for performance
A list of optional features to customize user experience
Which item is typically included in a baseline’s settings to enhance security?
Game mode and screen refresh rates
Font libraries and color profiles
Password policies and user rights
Wallpaper themes and desktop icons
Which benchmark is widely recognized as an industry standard for secure configuration?
HTML5 accessibility rules
CIS Benchmarks for systems
PCI DSS merchant tiers
IEEE 802.11 wireless profiles
Which standard is specifically used by the U.S. Department of Defense for system hardening?
DISA STIG guidance
ISO 8601 dates
TLS 1.3 cipher suites
W3C web specifications
Why should organizations follow a baseline across all servers?
It guarantees faster boot times regardless of hardware
It eliminates the need for monitoring and logging
It ensures consistent security posture and reduces misconfigurations
It prevents all zero-day exploits without patches
Which example best represents a before/after hardening comparison?
Measuring disk space used by photos
Documenting open ports reduced and services disabled
Listing favorite applications installed by users
Comparing CPU temperatures during gaming sessions
How do vendor baselines, like Microsoft or Red Hat recommendations, help security teams?
They provide comprehensive documentation to aid audits and compliance
They automate all incident response tasks without analysts
They replace the need for network firewalls entirely
They guarantee no vulnerabilities will ever be found
