A security team managing an isolated air-gapped operational technology (OT) network discovers widespread configuration drift across engineering workstations during a compliance audit. Simultaneously, a critical zero-day vulnerability advisory requires immediate software updates on these systems. Which of the following procedures should the security team implement to remediate the configuration drift while safely deploying emergency security patches? (Select TWO).
- Establish a validated baseline using configuration audit scripts in an isolated staging environment before applying signed offline patch packages via inspected media.Answer
- Conduct a formal change advisory board (CAB) review to approve emergency deployment windows and verified system rollback points prior to production deployment.Answer
- CTemporarily connect the OT network segment to the enterprise cloud management console to enable direct real-time patch streaming and automated baseline enforcement.
- DDeploy inline host-based intrusion prevention blocking rules across all programmable logic controllers to act as a permanent replacement for operating system patches.
Answer
The security team should establish a validated configuration baseline in an isolated staging environment using signed offline patch packages, and conduct a formal change advisory board review with defined rollback points before updating production systems.
Remediating configuration drift and vulnerabilities in air-gapped environments requires staging offline, cryptographically signed updates to maintain network isolation, alongside rigorous change control processes including rollback planning to protect operational stability.
Step-by-Step Solution
Key Concept
Air-Gapped Patch Management and Configuration Baseline Enforcement