How to Decrease Hardware Attack Surface?
Which of the following should a systems administrator use to decrease the company's hardware attack surface?
Community Votes
64% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between physical resource consolidation and logical security controls, with the common trap being the selection of isolation, which mitigates risk without actually reducing the physical hardware footprint.
Virtualization reduces a company's hardware attack surface by consolidating multiple workloads onto fewer physical servers, directly minimizing the number of physical devices that require security and maintenance. This approach aligns with the majority community consensus and CompTIA's focus on infrastructure optimization.
Candidates frequently select Isolation (B), reasoning that network or system segmentation limits attacker movement and exposure; however, isolation is a defensive control that contains breaches rather than a consolidation strategy that physically decreases the number of hardware components constituting the attack surface.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Hardware Attack Surface Reduction
The term hardware attack surface specifically refers to the total number of physical devices, ports, interfaces, and firmware components that could potentially be exploited by an attacker. By using virtualization, administrators consolidate multiple physical servers into virtual machines (VMs) running on a smaller pool of host hardware. As highlighted in community discussions, this consolidation minimizes the physical footprint, meaning there are fewer devices to patch, monitor, update, and secure, directly shrinking the hardware attack surface.
Why Other Options Are Incorrect
Isolation (B) is the most popular distractor. While isolation effectively limits lateral movement and contains potential breaches by segmenting networks or environments, it does not reduce the actual count of physical hardware components. It is a risk mitigation control, not a hardware consolidation technique.
Centralization (C) typically involves routing traffic through fewer core devices, which can actually increase hardware requirements for redundancy and high availability, potentially expanding the attack surface if not designed carefully.
Replication (A) creates duplicate copies of data or systems across additional physical hardware for disaster recovery or load balancing, which inherently increases the hardware attack surface rather than decreasing it.
Exam Context
The community vote split (D: 64, B: 36) highlights a common SY0-701 pattern where candidates confuse logical security boundaries with physical infrastructure optimization. CompTIA expects you to recognize that consolidation via virtualization is the primary architectural method for reducing physical hardware exposure.
Official Reference
Exam Strategy
Always pay close attention to the specific asset type mentioned in the question. When the prompt specifies reducing the hardware attack surface, prioritize answers related to consolidation, decommissioning, or lifecycle management over logical controls like segmentation, encryption, or isolation.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →