A system administrator has provisioned a new web server whic - CompTIA Cloud+ CV0-004

Question

A system administrator has provisioned a new web server. Which of the following, in combination, form the best practice to secure the server's OS? (Choose three.)

Answers
  1. correct
  2. correct
  3. correct
Explanation

Correct Answers: c. Disable TLS 1.0/1.1 and SSL, e. Enable SSH key access only, h. Restrict access on port 22 to the IP address of the administrator's workstation

Disabling outdated protocols like TLS 1.0/1.1 and SSL improves security by preventing use of weak encryption. Enabling SSH key access only removes password-based vulnerabilities. Restricting port 22 access limits SSH connections to trusted IPs, reducing exposure to unauthorized login attempts.

Why the other options are incorrect:

  • a. Install TLS certificates on the server:
    Important for encrypting web traffic but primarily secures application-level communication, not the OS itself.

  • b. Forward port 80 traffic to port 443:
    Improves web traffic security by redirecting HTTP to HTTPS, but doesn’t directly secure the OS.

  • d. Disable password authentication:
    Similar to enabling SSH key access, but without specifying key access only, this is incomplete as it may disable all authentication if not managed properly.

  • f. Provision the server in a separate VPC:
    Network segmentation is good practice but not directly an OS security control.

  • g. Disable the superuser/administrator account:
    Disabling default admin accounts is often not feasible; better practice is to restrict access or rename the account rather than disable it completely.

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered