What Should a Security Team Do First Before Deploying a New Web Server?
Which of the following should a security team do first before a new web server goes live?
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests understanding of defense-in-depth sequencing and the hierarchy of security controls, trapping candidates who prioritize tactical vulnerability remediation over comprehensive baseline hardening.
This question evaluates the correct sequence of security controls during server deployment, emphasizing that baseline hardening establishes the necessary secure foundation. While the official answer prioritizes host hardening, the community remains split, with many arguing that applying patches logically precedes configuration adjustments.
Many candidates select D (Apply patch management) because remediating known CVEs feels like the most immediate and measurable action. They overlook that patching is actually a subset of the broader hardening process, which must be initiated first to establish a secure configuration baseline and prevent systemic instability.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
The Foundation: Host Hardening Comes First
The correct answer is A. Harden the virtual host. Before any application or service is exposed to a network, the underlying system must be secured through a comprehensive hardening process. Hardening establishes the security baseline by disabling unused ports and services, enforcing strict file permissions, configuring secure authentication mechanisms, and applying initial firewall rules. As noted by community members, hardening is an umbrella activity that inherently includes patching, making it the logical first step in the deployment lifecycle.
Why Patch Management Takes a Backseat Initially
Many candidates incorrectly choose D. Apply patch management because fixing known vulnerabilities feels like the most urgent task. However, patching is technically a component of the hardening workflow. You cannot effectively apply patches until the host has been provisioned, configured, and hardened to prevent misconfigurations from masking vulnerabilities or causing system instability. Commenters frequently debate this distinction, but certification exams prioritize the architectural sequence where baseline configuration precedes ongoing maintenance tasks like patching.
Monitoring and Application-Layer Defenses Follow Later
Options B and C represent defensive measures that belong in later phases. Web Application Firewall (WAF) rules are crafted after the application logic is deployed and understood, while Network Intrusion Detection Systems (NIDS) require network segmentation and traffic baselining. Implementing these before the server is even hardened would result in excessive false positives and operational chaos. The SY0-701 exam consistently tests the principle that you must secure the foundation before layering on specialized controls.
Official Reference
Exam Strategy
When facing deployment sequence questions, always look for the option that establishes the foundational security posture rather than tactical maintenance tasks. If a choice represents a broad security framework and another represents a specific action within that framework, select the broader framework as the initial step.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →