What Should a Security Team Do First Before Deploying a New Web Server?

Which of the following should a security team do first before a new web server goes live?

  1. Harden the virtual host. Source Reference Answer
  2. Create WAF rules.
  3. Enable network intrusion detection.
  4. Apply patch management.

Community Votes

A
57%
D
43%

57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests understanding of defense-in-depth sequencing and the hierarchy of security controls, trapping candidates who prioritize tactical vulnerability remediation over comprehensive baseline hardening.

This question evaluates the correct sequence of security controls during server deployment, emphasizing that baseline hardening establishes the necessary secure foundation. While the official answer prioritizes host hardening, the community remains split, with many arguing that applying patches logically precedes configuration adjustments.

Many candidates select D (Apply patch management) because remediating known CVEs feels like the most immediate and measurable action. They overlook that patching is actually a subset of the broader hardening process, which must be initiated first to establish a secure configuration baseline and prevent systemic instability.

Community Discussion (9 comments)

Anyio 👍 5 Selected: A
The correct answer is: A. Harden the virtual host. Explanation: Hardening the virtual host is the first step a security team should take before a new web server goes live. This involves securing the server by removing unnecessary services, applying secure configurations, and minimizing potential attack surfaces. Hardening ensures the server is in a secure state before it is exposed to potential threats. Create WAF rules (B) is important but should be done after the server is hardened, as the Web Application Firewall (WAF) rules depend on the server's configuration and applications. Enable network intrusion detection (C) is a broader network security measure and should be implemented after the server itself is secured. Apply patch management (D) is critical but is part of the ongoing maintenance process and should follow initial hardening. Thus, hardening the virtual host is the first and most critical step to ensure the web server is secure before it goes live.
MarysSon 👍 1 Selected: A
Harden the virtual host is more logical. While applying patches is necessary, the activity is a subset of hardening the host. Patches defend against commonly known vulnerabilities, but hardening does more
tomahawk117 👍 3 Selected: D
The question says nothing about a a virtual host. After setting a new web server you'll want to make sure its patched.
jbmac 👍 3 Selected: D
The correct answer is: D. Apply patch management. Explanation: Before a new web server goes live, the first thing the security team should do is ensure that the server is patched. Patch management ensures that all known vulnerabilities in the operating system, software, and web server components are addressed. This is crucial to minimize the attack surface and prevent exploitation of known vulnerabilities. Applying the latest patches is a foundational step in securing any system before it is exposed to the internet.
Fhaddad81 👍 3
Why not b Create WAF rules.?
kippedwards8 👍 2 Selected: A
A. Harden the virtual host This is the correct answer according to chat GPT
Fourgehan 👍 3 Selected: A
Before a new web server goes live, the first step should be to harden the virtual host, which involves securing the server by: Disabling unnecessary services and ports. Configuring secure protocols. Setting strong authentication and authorization policies. Ensuring file permissions and directory structures are appropriately configured. Hardening ensures that the server's baseline security posture is strong and minimizes vulnerabilities that attackers could exploit
Segunmx 👍 1 Selected: A
A. Harden the virtual host. Explanation: Before a new web server goes live, hardening the virtual host should be the first step. Hardening involves configuring the server to reduce vulnerabilities and enhance security.
Cocopqr 👍 3 Selected: D
D. Apply patch management. Patching the server first ensures it's up-to-date and less vulnerable to attacks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

The Foundation: Host Hardening Comes First

The correct answer is A. Harden the virtual host. Before any application or service is exposed to a network, the underlying system must be secured through a comprehensive hardening process. Hardening establishes the security baseline by disabling unused ports and services, enforcing strict file permissions, configuring secure authentication mechanisms, and applying initial firewall rules. As noted by community members, hardening is an umbrella activity that inherently includes patching, making it the logical first step in the deployment lifecycle.

Why Patch Management Takes a Backseat Initially

Many candidates incorrectly choose D. Apply patch management because fixing known vulnerabilities feels like the most urgent task. However, patching is technically a component of the hardening workflow. You cannot effectively apply patches until the host has been provisioned, configured, and hardened to prevent misconfigurations from masking vulnerabilities or causing system instability. Commenters frequently debate this distinction, but certification exams prioritize the architectural sequence where baseline configuration precedes ongoing maintenance tasks like patching.

Monitoring and Application-Layer Defenses Follow Later

Options B and C represent defensive measures that belong in later phases. Web Application Firewall (WAF) rules are crafted after the application logic is deployed and understood, while Network Intrusion Detection Systems (NIDS) require network segmentation and traffic baselining. Implementing these before the server is even hardened would result in excessive false positives and operational chaos. The SY0-701 exam consistently tests the principle that you must secure the foundation before layering on specialized controls.

Official Reference

Exam Strategy

When facing deployment sequence questions, always look for the option that establishes the foundational security posture rather than tactical maintenance tasks. If a choice represents a broad security framework and another represents a specific action within that framework, select the broader framework as the initial step.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide