Which of the following preventative controls would be appropriate for responding to a
directive to reduce the attack surface of a specific host?

A.
Installing anti-malware
B.
Implementing an IDS
C.
Taking a baseline configuration
D.
Disabling unnecessary services
Why not A?
0
0
because installing anti-malware is increasing the attack surface
0
0
Care to explain?
0
0
Think of this like Risk avoidance. Eliminating unnecessary services all but eliminates their risk of being exploited.
0
0