A SOC analyst reviews a server build template that disables unused services, removes legacy protocols, and enforces secure defaults before deployment. The organization uses the template to reduce exposure before an attacker can exploit weak configurations. Which control type best describes this template?
Select an answer to reveal the explanation.
Short Explanation
Think of a hardened baseline like locking every unused door before the party starts. If you're alerting after the fact, that's detective, not this. The trap is confusing a control that stops exploitation with one that detects or repairs it.
Full Explanation
A configuration baseline that disables unused services and enforces secure defaults acts before an adversary can exploit a weakness, so it is a preventive control. Prevention is chosen when the goal is to reduce the attack surface and lower the probability of successful exploitation. A baseline is applied during build or deployment, making it proactive rather than reactive. A detective control would be wrong because it focuses on identifying suspicious behavior after a weakness is used, such as logging, monitoring, or alerting on anomalous service activity. A corrective control would be wrong because it responds after an incident or finding, such as patching, rebuilding, or removing a compromised service. A compensating control would be wrong because it substitutes for a primary control when that control cannot be implemented, such as network segmentation replacing an unavailable host firewall feature. Exam caveat: CS0-004 expects you to classify controls by timing and purpose, not by tool name. Operational check: Review build templates and confirm each disabled service, removed default, and enforced setting is mapped to a risk-reduction objective before deployment.