Which two components decrease the attack surface on an endpoint?
Secure Boot validates boot components so that untrusted or malicious software cannot load during system startup. Restricting USB ports limits connection of untrusted peripheral and removable-storage devices, reducing opportunities for malware, unauthorized access, and data loss. Secure Boot and Trusted Boot and Device control in Microsoft Defender for Endpoint describe these protections.
Community Discussion