CompTIA Server+ SK0-005 Practice Question
During a quarterly security assessment of your organization's virtualization cluster, you discover that anyone who presses F2 during POST can enter the host's UEFI Setup utility and disable Secure Boot or alter the boot order. The servers must continue to reboot automatically after scheduled patching with no human intervention. Which hardening control best prevents unauthorized firmware changes without disrupting unattended restarts?
Enable a power-on (system) password that must be entered at every boot
Install a chassis-intrusion switch and log any tamper events
Disable all unused USB ports from the firmware's device-control menu
Configure a supervisor (setup/administrator) password in the UEFI firmware