adplus-dvertising
frame-decoration

Question

When should system hardening activities take place?

a.

When the system is initially built

b.

When the system is initially built and periodically during its life

c.

When the system is initially built and when it is decommissioned

d.

When the system is initially built, periodically during its life, and when it is decommissioned

Answer: (b).When the system is initially built and periodically during its life Explanation:System hardening should take place when a system is initially built and periodically during its life. There is no need to harden a system prior to decommissioning because it is being shut down at that point.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. When should system hardening activities take place?

Similar Questions

Discover Related MCQs

Q. Which one of the following techniques is not an appropriate remediation activity for a SQL injection vulnerability?

Q. Which one of the following is not an example of an operational control that might be implemented to remediate an issue discovered during a penetration test?

Q. Who is the most effective person to facilitate a lessons learned session after a penetration test?

Q. Which one of the following activities is not commonly performed during the post-engagement cleanup phase?

Q. Which one of the following items is not appropriate for the executive summary of a penetration testing report?

Q. Tom’s organization currently uses password-based authentication and would like to move to multifactor authentication. Which one of the following is an acceptable second factor?

Q. Gary ran an Nmap scan of a system and discovered that it is listening on port 22 despite the fact that it should not be accepting SSH connections. What finding should he report?

Q. Which one of the following is not a normal communication trigger for a penetration test?

Q. Wendy is reviewing the results of a penetration test and learns that her organization uses the same local administrator password on all systems. Which one of the following tools can help her resolve this issue?

Q. What type of report is the client requesting when they ask for a letter documenting the penetration test results for compliance files?

Q. What should testers observe regarding data retention and destruction at the conclusion of a penetration testing engagement?

Q. What does the level of detail in a formal attestation of findings depend on?

Q. When might a formal attestation of findings be requested in a penetration testing engagement?

Q. What might be included in follow-up actions after a penetration testing engagement?

Q. Why is it often helpful to have a third party moderate the lessons learned session in a penetration testing engagement?

Q. What is the purpose of the lessons learned session in a penetration testing engagement?

Q. What is the purpose of obtaining formal client acceptance in a penetration testing engagement?

Q. What are three important post-engagement cleanup activities highlighted by CompTIA?

Q. What is a basic principle that penetration testers should follow during post-engagement cleanup?

Q. What is an essential post-report delivery activity for penetration testers before closing out a project?