A security analyst is investigating configuration compliance reports across an operational technology (OT) environment managed by an automated deployment framework. Although the centralized dashboard reports full compliance with the organization's hardened baseline template, manual vulnerability audits reveal that several controllers have unapproved network services active and customized settings configured locally. Further inspection indicates that local system administrators made manual adjustments directly on the devices, leading to configuration drift that was not detected or overridden by the centralized management tool. Which of the following actions should the security analyst perform FIRST to permanently address the configuration drift and restore baseline integrity?
- Configure continuous automated enforcement and drift remediation within the centralized configuration management framework to automatically detect and overwrite unapproved local changes.Answer
- BDeploy host-based firewall rules across the affected controllers to block traffic routed to the newly exposed service ports.
- CReclassify the mandatory hardening benchmark as an optional administrative guideline for operational technology endpoints.
- DIssue an emergency out-of-band operating system patch deployment to update the firmware binaries on all OT controllers.