Which of the following is the best security reason for closing service ports that are not needed?
Choose an answer
Tap an option to check your answer.
Correct answer: To reduce a system's attack surface.
Why this is the answer
Closing unneeded service ports directly reduces a system's attack surface. The attack surface comprises all points where an unauthorized user can try to enter or extract data from an environment. Fewer open ports mean fewer potential entry points for attackers to exploit vulnerabilities, launch denial-of-service attacks, or gain unauthorized access. "To mitigate risks associated with unencrypted traffic" is incorrect because closing ports doesn't inherently encrypt traffic; it only prevents traffic from using those specific ports. "To eliminate false positives from a vulnerability scan" is incorrect because while it might reduce some scan findings, the primary security benefit isn't about scan accuracy but about actual risk reduction. "To improve a system's resource utilization" is incorrect because while closing ports might free up minimal resources, the primary motivation is security, not performance optimization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed