Which of the following should a security team do first before a new web server goes live?
Choose an answer
Tap an option to check your answer.
Correct answer: Harden the virtual host..
Why this is the answer
Hardening the virtual host is the most critical first step. This involves configuring the operating system and web server software with security best practices, such as disabling unnecessary services, closing unused ports, applying least privilege, and securing configuration files. This foundational security reduces the attack surface significantly before the server is exposed to any traffic. While creating WAF rules, enabling network intrusion detection, and applying patch management are all crucial security measures, they are typically performed after the initial host hardening. WAF rules protect against web-specific attacks, NIDS detects malicious network activity, and patch management ensures ongoing security updates. However, if the underlying host is not hardened, these subsequent layers may be less effective against fundamental vulnerabilities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed