TechKnowSurge
NIST 800-53 SI-3 CompTIA A+ Core 2 2.1 CompTIA Security+ 4.1 Cisco CCST Cybersecurity 3.1 NIST 800-53 CM-6 ISC2 CC 5.4 CompTIA A+ Core 2 2.5 Cisco CCST Cybersecurity 3.3
InteractiveSecurityFree

Pick the Host Control

Stolen laptop, strange behavior, a lab PC to keep clean, updates nobody installs: which host control solves it?

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Host-based security is what you do on the laptops, desktops and other end-user devices themselves. - Host-based firewall and HIDS/HIPS: the same ideas as the network's firewall and IDS/IPS, but in software on one machine (Windows has a firewall built in). Keep them on and up to date, and turn off ports and protocols the machine does not use. - Harden the operating system: disable unused services, install only what is needed, patch it and update its drivers. - Antivirus or anti-malware scans files and code for malicious software. EDR (endpoint detection and response) goes a step further and looks at behavior: is something odd happening on this machine? (Modern antivirus has some behavior checks too, but scanning for known malware is its core; recording and responding to behavior is EDR's.) - Privileged accounts: users do not get admin rights, and even IT staff use a separate admin account for admin work. - Safe browsing and content filtering, above all on servers. - Disk imaging (cloning): a copy of a hardened machine, used to set up new machines quickly, or to wipe an infected one and restore it to the known-good state. Deep Freeze keeps a machine in a frozen state: users can change anything, and it all disappears when the machine restarts. (The video says it resets when the user logs off; Deep Freeze restores the frozen state on a restart.) - Disk encryption, such as BitLocker on Windows, so a stolen laptop or phone does not give up its data. - Patch management: users will not reliably update, so updates are tested, deployed consistently, tracked and documented, for applications as well as the operating system. - Group Policy applies settings, such as idle timeouts, screen locks and password rules, to every Windows machine at once. Mobile device management (MDM) does the same job for phones and tablets. - Monitoring: check that all of this is really happening, with logs and alerts.

What you'll learn

Aligned to

NIST 800-53
SI-3 Malicious Code Protection
CM-6 Configuration Settings
CompTIA A+ Core 2
2.1 Summarize various security measures and their purposes.
2.5 Given a scenario, manage and configure basic security settings in the Microsoft Windows OS.
CompTIA Security+
4.1 Given a scenario, apply common security techniques to computing resources.
Cisco CCST Cybersecurity
3.1 Describe operating system security concepts
3.3 Verify that endpoint systems meet security policies and standards
ISC2 CC
5.4 Understand asset protection

Key terms

Host-based Firewall
A software firewall installed directly on an individual computer that monitors and controls network traffic to and from that specific host. Host-based firewalls provide a layer of defense that persists even when a device leaves the corporate network.
Antivirus
Software designed to detect, prevent, and remove malicious software from a system.
Endpoint Detection and Response
EDR
A security solution that continuously monitors endpoint devices to detect, investigate, and respond to threats.
Full Disk Encryption
FDE
Full Disk Encryption is a method of encrypting all data on a storage device at the hardware or software level, ensuring that data remains inaccessible if the device is lost or stolen without the proper authentication credentials or decryption key.
BitLocker
BitLocker is Microsoft Windows' built-in full-volume encryption feature that uses AES to protect data on drives, leveraging TPM hardware to bind encryption keys to a specific system configuration.
Disk Imaging
The process of creating an exact copy of a configured and hardened system that can be deployed to other machines or used to restore a compromised host.
Reimaging
The process of wiping a compromised system and reinstalling the operating system and software from a clean image to ensure complete removal of threats.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Group Policy
A Windows feature that allows administrators to centrally define and enforce security configurations — such as password complexity rules, screen lock timeouts, and software restrictions — across all machines in an Active Directory domain.
Mobile Device Management
MDM
Mobile Device Management is a software solution that enables organizations to remotely enroll, configure, monitor, and enforce security policies on employee mobile devices, including the ability to wipe lost or compromised devices.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.

Topics

Endpoint Detection And Response Patch Management Group Policy Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →