Req 2.2.2 requires enabling only necessary services, protocols, and daemons. Which action demonstrates this?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Req 2.2.2 requires enabling only necessary services, protocols, and daemons. Which action demonstrates this?

Explanation:
Minimizing exposed services reduces the attack surface by ensuring only what is truly needed is available. This question tests the practice of validating server configurations to match a approved baseline, so only necessary services, protocols, and daemons are enabled. The action of inspecting what is currently enabled and verifying that only the required items are active demonstrates this approach in action—it's about actively confirming and enforcing the chosen, minimal set of operational components. By contrast, auditing only network devices misses the server configuration, enabling all services by default unnecessarily broadens exposure, and removing all security configurations would destroy protection and violate PCI DSS controls.

Minimizing exposed services reduces the attack surface by ensuring only what is truly needed is available. This question tests the practice of validating server configurations to match a approved baseline, so only necessary services, protocols, and daemons are enabled. The action of inspecting what is currently enabled and verifying that only the required items are active demonstrates this approach in action—it's about actively confirming and enforcing the chosen, minimal set of operational components. By contrast, auditing only network devices misses the server configuration, enabling all services by default unnecessarily broadens exposure, and removing all security configurations would destroy protection and violate PCI DSS controls.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy