Question 1
A system administrator is hardening a new FreeBSD server that will host critical financial data. A primary requirement is to prevent any modifications to kernel modules at runtime, even by the root user, once the system is fully booted. Which configuration in /etc/sysctl.conf will achieve this specific security objective?
Answer and explanation
Correct answer: B
Setting kern.securelevel to 2 provides all the protections of level 1 (such as immutable file flags and preventing writing to raw disk devices) and additionally prevents the loading or unloading of kernel modules. This directly meets the requirement of preventing runtime modifications to kernel modules.