Q: 15
[Security Architecture]
A security architect must make sure that the least number of services as possible is exposed in order
to limit an adversary's ability to access the systems. Which of the following should the architect do
first?
Options
Discussion
B tbh
B/C? If attack surface reduction includes disabling unnecessary services, then B is more accurate technically.
C vs B. I could see why someone might pick C since cutting third-party integrations seems like it would reduce exposure, but "attack surface reduction" (B) is usually the more comprehensive first move. Still, C can be a tempting trap option.
Why not D? Wouldn’t limiting access also reduce exposed services technically?
Be respectful. No spam.