Hardening

Reducing attack surface by removing unneeded services, accounts, and features.

Hardening shrinks the attack surface by removing unneeded services, default accounts, open ports, and features, then enforcing secure settings. Use a recognized baseline like CIS Benchmarks or DISA STIGs as the target. It’s most effective baked into golden images and provisioning automation rather than bolted on after deployment, where drift and missed hosts creep in.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Security Operations