Soru

Zorluk: ZorWorkstation Hardening and Best Practices

An IT specialist is configuring several Windows 11 workstations deployed in a shared corporate training center. The systems must allow external guest speakers to plug in USB presentation remotes and keyboards, but security policy strictly prohibits executable files from automatically launching when USB flash drives are inserted. Which of the following is the most effective workstation hardening practice to satisfy this requirement without disabling essential USB input devices?

  1. Configure Administrative Templates in Group Policy to disable the AutoPlay feature for all drives.Cevap
  2. B
    Disable the USB host controller and root hubs using Device Manager.
  3. C
    Enable the local Guest account and grant it Read & Execute permissions on all removable storage volumes.
  4. D
    Open the Credential Manager Control Panel applet and remove all stored Windows credentials.

Cevap

Disabling the AutoPlay feature for all drives via Group Policy prevents automatic execution of software from removable storage media while keeping physical USB ports operational for essential input peripherals.
Disabling AutoPlay for all drives via Group Policy explicitly stops Windows from executing automated commands or launching software installers when removable storage media is attached. This directly mitigates malicious code execution from flash drives while keeping USB bus controllers active so that external keyboards and presentation pointers operate as intended.

Adım Adım Çözüm

1
Analyze the security requirement and operational constraints.
Identified that removable storage auto-execution must be blocked, but physical USB ports must remain active for Human Interface Devices (HIDs).
Completely disabling USB ports or controllers would break required keyboard and presentation remote functionality.
2
Evaluate operating system policy controls that regulate removable media execution.
Determined that AutoPlay and AutoRun policies govern automated script/executable launching upon volume mounting.
Group Policy provides targeted control over storage drive behavior without affecting non-storage USB peripherals.
3
Select the appropriate Group Policy hardening configuration.
Navigated to Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies and set 'Turn off AutoPlay' to Enabled for all drives.
This baseline hardening step eliminates the primary attack vector of autorun malware from flash drives while maintaining full support for input peripherals.

Anahtar Kavram

Workstation Hardening - Disabling AutoPlay and AutoRun Policies
Tahmini Süre:1m 30s
Bu soruyu puanla