Soru

Zorluk: Çok zorWorkstation Hardening and Best Practices

A security analyst is defining baseline system hardening guidelines for enterprise workstations deployed in a corporate environment. The objective is to mitigate legacy network credential spoofing vulnerabilities and reduce the local attack surface against targeted brute-force attempts on default administrative privileges. Which of the following technical hardening measures should be implemented to achieve these specific security objectives? (Select TWO.)

  1. Disable built-in Guest accounts and rename default local Administrator accounts.Cevap
  2. Disable legacy name resolution protocols including LLMNR and NetBIOS over TCP/IP.Cevap
  3. C
    Configure Event Viewer to dynamically identify and block unauthenticated incoming network connections.
  4. D
    Deploy screen privacy filters and physical cable locks to eliminate remote network attack vectors.

Cevap

Disabling built-in Guest accounts and renaming default Administrator accounts, along with disabling legacy name resolution protocols like LLMNR and NetBIOS over TCP/IP, are the proper technical controls to satisfy these hardening requirements.
The correct hardening measures involve disabling built-in Guest accounts and renaming default local Administrator accounts to restrict local account exploitation, as well as disabling unneeded legacy name resolution protocols (LLMNR and NetBIOS over TCP/IP) to prevent local broadcast spoofing and credential sniffing.

Adım Adım Çözüm

1
Identify local account hardening controls to minimize brute-force targeting of well-known accounts.
Disabling the built-in Guest account removes unauthenticated access, and renaming the default Administrator account prevents automated targeted attacks against known SID/username combinations.
Default administrative account names are primary targets for automated exploits and dictionary attacks.
2
Identify network protocol hardening controls to mitigate local network spoofing.
Disabling LLMNR and NetBIOS over TCP/IP prevents falling back to unauthenticated broadcast name resolution when DNS fails.
Attackers exploit fallback broadcast protocols like LLMNR/NBT-NS using tools like Responder to harvest NTLM challenge responses.
3
Evaluate and eliminate incorrect administrative tool and physical control options.
Event Viewer is an auditing tool rather than a network filter, and physical security controls do not mitigate remote network-based exploits.
Workstation hardening requires applying appropriate logical security configurations matching the specific threat vector.

Anahtar Kavram

Workstation Hardening and Best Practices
Bu soruyu puanla