System and Endpoint Hardening Questions

Making operating systems, hosts, and endpoints resistant to compromise. Covers secure baseline configuration (CIS Benchmarks, Microsoft security baselines) and drift against the baseline, including detecting drift and deciding what to report versus auto-correct, OS and application hardening for Linux and Windows (SSH, host firewalls, service minimization, SELinux and AppArmor, file permissions, least privilege, application allow-listing, local administrator accounts), patch management and rollout (asset inventory, prioritisation, patch cadence, deployment rings and canaries, maintenance windows, emergency and out-of-cycle patching, post-patch verification, rollback, patch compliance metrics, immutable images, Windows and Linux update tooling such as Windows Update for Business, Intune, WSUS, Configuration Manager and Azure Update Manager), scripted audits and enforcement of host settings (Ansible, PowerShell, shell), and the host-side conditions that protect an endpoint (device posture checks, disk encryption, protection agent status). The host-level preventive layer. Detecting and investigating attacks, vulnerability scanning and scoring, network device and perimeter security, identity and key management, Active Directory attack hardening, operating WSUS or ConfigMgr as server roles, and container platform security are covered elsewhere.

HardTechnical
55 practiced

A hardened baseline keeps drifting once servers are in production. Design how you would detect drift against it across Windows and Linux hosts, and how you decide per setting between reporting only and fixing it automatically.

MediumTechnical
83 practiced

A new Windows server has just been provisioned and should have your organisation's hardening baseline applied through Group Policy and local hardening scripts. How do you verify automatically that it really applied, which commands and logs do you inspect, and how do noncompliant hosts get surfaced to the team?

EasyTechnical
48 practiced

What does least privilege mean on a host, and how would you actually enforce it for users, files and directories on both Windows and Linux?

MediumTechnical
46 practiced

Your organisation runs about 1,000 mixed Windows and Linux servers, on-prem and in cloud, with no consistent security baseline. Design the programme that gets them to one and keeps them there: what you enforce first, how you enforce it, how you prove it, and how you decide what to leave out.

MediumTechnical
59 practiced

Write a script that compares a security baseline for a Linux host (SSH settings, sysctl values, file modes, enabled services) against the host's current state and reports drift as a short human-readable summary plus machine-readable JSON. The baseline can have missing keys and per-setting defaults. How do you structure the comparison so that adding a new kind of check is easy?

Unlock Full Question Bank

Get access to all 22 System and Endpoint Hardening interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.