Soru

Zorluk: OrtaWorkstation Hardening and Best Practices

A systems technician is configuring security hardening settings on newly deployed Windows workstations used in a retail environment as point-of-sale terminals. To reduce the system's attack surface and prevent unauthorized automated execution of malicious files from USB flash drives, which of the following administrative actions should the technician perform?

  1. Disable the built-in Guest account and configure the Group Policy setting to turn off AutoPlay for all drives.Cevap
  2. B
    Demote the Administrator account to the Guest group and set User Account Control (UAC) notifications to 'Never Notify'.
  3. C
    Open Event Viewer in Computer Management and set the Windows Defender Service startup type to Disabled.
  4. D
    Configure Privacy Settings in Control Panel to lock the computer case and restrict physical port access.

Cevap

Disable the built-in Guest account and configure the Group Policy setting to turn off AutoPlay for all drives.
Disabling default built-in accounts (such as the Guest account) eliminates unnecessary access pathways into the operating system. Disabling AutoPlay/AutoRun via Group Policy prevents Windows from automatically executing software stored on inserted USB drives, protecting the workstation from autorun-based malware.

Adım Adım Çözüm

1
Identify the key security goals from the scenario: reducing attack surface by removing unused access points and preventing automatic execution of media on USB drives.
Recognized that disabling default local accounts and disabling AutoPlay are standard OS hardening controls.
Default accounts like Guest provide unauthenticated local access, and AutoPlay poses a risk of malware auto-execution from removable storage.
2
Evaluate the available administrative policies and security configurations.
Disabling the Guest account stops unauthorized access, and setting the Group Policy to turn off AutoPlay for all drives blocks automatic execution of scripts or binaries when USB devices are attached.
These controls directly mitigate the threats mentioned in the requirement.

Anahtar Kavram

Workstation Hardening Best Practices - Account Management and AutoPlay Policies
Bu soruyu puanla