From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Insecure configurations and improper patching

Insecure configurations and improper patching

From the course: CompTIA SecurityX (CAS-005) Cert Prep

Insecure configurations and improper patching

- In this lesson, let's start out looking at some techniques for reducing the attack surface due to insecure or unsecure configuration. One way is to change the default credentials. Always change default usernames and passwords on all your systems and devices. Default credentials are common targets for attackers. Remember to apply the least privileged principle, reducing the risk of unauthorized access. Conduct regular patching and updates, but make sure you test those patches and updates in a prototypical or a sandbox environment first. Reducing the attack surface through hardening and disabling unnecessary services. Implement strong access controls, multifactor authentication, and not just strong password, but maybe passwordless solutions like FIDO2. Use configuration management tools to enforce security policies and ensure consistent configurations across all systems. Do regular audits and assessments. We also want to mitigate misconfiguration with our directory services, so let's…

Contents