Question

Difficulty: Very hardPatch and Configuration Management

A security team managing an isolated air-gapped operational technology (OT) network discovers widespread configuration drift across engineering workstations during a compliance audit. Simultaneously, a critical zero-day vulnerability advisory requires immediate software updates on these systems. Which of the following procedures should the security team implement to remediate the configuration drift while safely deploying emergency security patches? (Select TWO).

  1. Establish a validated baseline using configuration audit scripts in an isolated staging environment before applying signed offline patch packages via inspected media.Answer
  2. Conduct a formal change advisory board (CAB) review to approve emergency deployment windows and verified system rollback points prior to production deployment.Answer
  3. C
    Temporarily connect the OT network segment to the enterprise cloud management console to enable direct real-time patch streaming and automated baseline enforcement.
  4. D
    Deploy inline host-based intrusion prevention blocking rules across all programmable logic controllers to act as a permanent replacement for operating system patches.

Answer

The security team should establish a validated configuration baseline in an isolated staging environment using signed offline patch packages, and conduct a formal change advisory board review with defined rollback points before updating production systems.
Remediating configuration drift and vulnerabilities in air-gapped environments requires staging offline, cryptographically signed updates to maintain network isolation, alongside rigorous change control processes including rollback planning to protect operational stability.

Step-by-Step Solution

1
Evaluate patch deployment methods compatible with air-gapped security boundaries.
Identify that offline, cryptographically signed patch packages tested on staging environments preserve network isolation while remediating vulnerabilities.
Direct internet or cloud connections undermine the security posture of air-gapped industrial environments.
2
Integrate emergency remediation with formal change management processes.
Obtain Change Advisory Board approval and verify restore/rollback capabilities prior to modifying production configurations.
Operational technology environments require strict change governance to prevent system instability during emergency patch deployment.
3
Reject ineffective compensating controls and unauthorized architecture changes.
Discard options suggesting temporary network bridging or using IPS rules as permanent replacements for OS software patches.
Compensating controls do not eliminate underlying software flaws or baseline drift, and bridging networks violates isolation requirements.

Key Concept

Air-Gapped Patch Management and Configuration Baseline Enforcement
Rate this question