Question 1Objective 4.1
Which set of actions is an example of hardening a new Linux server?
Many scenarios turn on a port number: an exposed database, a cleartext login, the secure replacement for an old protocol. These are the common ones.
| Rule of thumb | Prefer the encrypted protocol; close every port a system does not need |
|---|
| Port | Protocol | Secure choice |
|---|---|---|
| 21 | FTP | SFTP over SSH (22) or FTPS |
| 22 | SSH, SFTP, SCP | Already encrypted |
| 23 | Telnet | SSH (22) |
| 25 | SMTP relay | SMTP with STARTTLS; 587 for submission |
| 53 | DNS | DNSSEC for integrity |
| 80 | HTTP | HTTPS (443) |
| 110 / 143 | POP3 / IMAP | POP3S (995) / IMAPS (993) |
| 161 / 162 | SNMP | SNMPv3 |
| 389 | LDAP | LDAPS (636) |
| 443 | HTTPS | Already encrypted with TLS |
| 445 | SMB | Restrict to internal networks |
| 3306 / 1433 | MySQL / Microsoft SQL Server | Never expose to the internet |
| 3389 | RDP | Behind a VPN or jump server |
Which set of actions is an example of hardening a new Linux server?
Company laptops are often left in taxis. Which control best protects the data on a lost laptop's drive?
A company wants every device plugged into an office network port to authenticate before it gets network access. Which standard does this?
No, but the common ones above come up often in scenarios and labs. Knowing the secure replacement for each is as useful as the number.
SSH encrypts the session. It should still be limited to the hosts that need it.