Hardening
Reducing a system's attack surface by removing unneeded software and services, closing ports, patching and applying secure settings, to bring it to a defined secure baseline.
Hardening is the work of taking a system from its default state to a secure configuration. Typical steps include removing software, accounts and services that are not needed, closing unused ports, changing default credentials, applying current patches, enabling logging, and setting configuration options to their secure values. The NIST glossary describes it as a process intended to eliminate a means of attack by patching vulnerabilities and turning off nonessential services. Published checklists supply the target settings: the CIS Benchmarks, the Security Technical Implementation Guides (STIGs) from the US Defense Information Systems Agency, and the checklists catalogued by the NIST National Checklist Program (SP 800-70).
Hardening and the security baseline are commonly confused. The baseline is the documented target configuration; hardening is the act of bringing a system to it. Least functionality is the principle behind much of the removal work, while change management and a configuration management database help keep the system from drifting away from the baseline afterwards.
Exam relevance: a scenario is likely to describe a newly deployed server with default settings and unused services, and ask for the protective step that was skipped. Candidates are expected to distinguish the baseline (the standard) from hardening (applying it), and to recognise removing unneeded functions as part of hardening rather than a separate control.