Req 2.2.2 requires enabling only necessary services, protocols, and daemons. Which action demonstrates this?

Boost your readiness for the PCI DSS Requirements Exam with engaging flashcards and comprehensive multiple choice questions. Each comes with hints and explanations to maximize your understanding!

Multiple Choice

Req 2.2.2 requires enabling only necessary services, protocols, and daemons. Which action demonstrates this?

Explanation:
Minimizing exposed services reduces the attack surface by ensuring only what is truly needed is available. This question tests the practice of validating server configurations to match a approved baseline, so only necessary services, protocols, and daemons are enabled. The action of inspecting what is currently enabled and verifying that only the required items are active demonstrates this approach in action—it's about actively confirming and enforcing the chosen, minimal set of operational components. By contrast, auditing only network devices misses the server configuration, enabling all services by default unnecessarily broadens exposure, and removing all security configurations would destroy protection and violate PCI DSS controls.

Minimizing exposed services reduces the attack surface by ensuring only what is truly needed is available. This question tests the practice of validating server configurations to match a approved baseline, so only necessary services, protocols, and daemons are enabled. The action of inspecting what is currently enabled and verifying that only the required items are active demonstrates this approach in action—it's about actively confirming and enforcing the chosen, minimal set of operational components. By contrast, auditing only network devices misses the server configuration, enabling all services by default unnecessarily broadens exposure, and removing all security configurations would destroy protection and violate PCI DSS controls.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy