An IT support technician is deploying networked smart HVAC controllers throughout a company's corporate office. The embedded operating systems on these controllers cannot support third-party endpoint security software, centralized domain joining, or local user credential management. Which of the following security practices should the technician implement to BEST secure these embedded systems against unauthorized network access?
- Place the embedded controllers on a dedicated, isolated VLAN with restrictive firewall rulesCevap
- BEnroll the embedded controllers into an enterprise Mobile Device Management (MDM) solution to enforce passcode policies
- CConnect the embedded controllers to the primary internal wireless network using legacy WPA2-Personal authentication
- DAttach physical privacy screens to the control displays of each HVAC unit to prevent unauthorized viewing
Cevap
Place the embedded controllers on a dedicated, isolated VLAN with restrictive firewall rules
Embedded systems and IoT devices often lack hardware resources or software support for standard endpoint protection and administrative agents. Placed on an isolated Virtual Local Area Network (VLAN) with strict firewall rules, these devices can perform necessary network functions without exposing the rest of the enterprise network to pivoting attacks if compromised.
Adım Adım Çözüm
Anahtar Kavram
Embedded System Hardening and Network Segmentation