350-201 exam dumps

350-201 practice question 55 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 55

Select 3

You are tasked with deploying a machine image for a new web application in your organization's cloud infrastructure. To ensure security, you must use a hardened machine image as part of the deployment process. Which of the following steps are essential to hardening the machine image before deployment?

  1. A

    Remove unnecessary software and services from the base image.

  2. B

    Use default administrative credentials for simplicity during deployment.

  3. C

    Apply the latest security patches and updates to the machine image.

  4. D

    Disable unused network ports and protocols.

  5. E

    Enable a guest account to allow easier troubleshooting post-deployment.

Show answer and explanation

Correct answers: A, C, D

Explanation

Hardening a machine image is a critical step in securing cloud deployments. This involves removing unnecessary components, applying updates to address vulnerabilities, and disabling unused ports or protocols to reduce the attack surface. Ensuring strong credentials and avoiding insecure practices, such as enabling unnecessary accounts, are also key to maintaining security.

  • A. Correct.

    Removing unnecessary software and services reduces the attack surface of the machine image, making it more secure.

  • B. Incorrect.

    Using default administrative credentials is a security risk, as these are often well-known and could lead to unauthorized access.

  • C. Correct.

    Applying the latest security patches and updates ensures that any known vulnerabilities are addressed prior to deployment.

  • D. Correct.

    Disabling unused network ports and protocols minimizes potential entry points for attackers, enhancing security.

  • E. Incorrect.

    Enabling a guest account can expose the system to unauthorized access and is not a recommended security practice.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam