Which of the following hardening techniques must be applied on a container image before deploying it to a production environment?
Remove default applications and disable Telnet are hardening techniques applied on a container image before deploying it to a production environment.
Both techniques enhance security by reducing the attack surface and eliminating unnecessary services that could be exploited in a production setting.
Removing default applications is critical because these applications can introduce vulnerabilities that attackers might exploit. By stripping down the container to only necessary components, the overall security posture is significantly improved.
While installing a Network Intrusion Prevention System (NIPS) can be part of a broader security strategy, it does not specifically pertain to hardening a container image itself. NIPS is typically deployed at the network level rather than modifying the container's configuration before production.
Disabling Telnet is an essential hardening measure as Telnet transmits data in plain text, making it susceptible to interception. Removing it ensures that only secure communication protocols, like SSH, are used, thereby protecting sensitive information.
Reconfiguring DNS does not directly contribute to hardening a container image. It is more relevant to network configuration and management rather than minimizing vulnerabilities within the container itself.
Adding an SFTP server may enhance file transfer security but does not address hardening the container image. This action could even introduce unnecessary complexity and potential vulnerabilities if not properly managed.
Deleting a public certificate can lead to issues with secure communications and is not a recommended hardening practice. Instead, proper certificate management is crucial for maintaining secure connections.
Hardening a container image before deploying it to production involves removing unnecessary applications and disabling insecure services like Telnet. These actions reduce vulnerabilities and enhance the security of the deployment. Other choices, while relevant to security, do not directly contribute to the hardening of the container image itself.
Related Questions
View allWhile a school district is performing state testing
Which of the following actions would prevent this issue?
A user sends an email that includes a digital signature for validation...
After multiple phishing simulations the Chief Security Officer announc...
Which of the following techniques can be used to sanitize the data con...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations