An organization manages a fleet of remote workstations that frequently drift from the established secure configuration baseline due to localized user modifications made while devices are offline. The security team requires a technical control that continuously audits system settings and automatically restores non-compliant configurations back to the approved baseline whenever devices re-establish network connectivity. Which of the following mechanisms best fulfills this requirement?
- Automated configuration management agents enforcing desired-state policiesAnswer
- BHost-based intrusion prevention system rules blocking file modification events
- CPeriodic detective controls utilizing scheduled manual audit log reviews
- DEdge firewall access control list rules restricting inbound management traffic
Answer
Automated configuration management agents enforcing desired-state policies
Automated configuration management software utilizing desired-state enforcement continuously monitors endpoint operating systems and applications against established secure baseline templates. When a system drifts from its designated baseline standard due to local user edits or unapproved software changes, the agent automatically reapplies the baseline settings as soon as policy synchronization occurs.
Step-by-Step Solution
Key Concept
Configuration Baseline Enforcement and Drift Remediation
Estimated Time:1m 30s