Soru

Zorluk: ZorWorkstation Hardening and Best Practices

An IT security analyst is tasked with implementing a workstation hardening baseline for desktop computers deployed in a sensitive healthcare records office. The hardening policy must specifically address three vulnerability vectors: preventing unauthorized access when staff step away briefly, preventing automated malware installation from attached flash drives, and reducing the local account attack surface. Which of the following configuration sets should the administrator apply to satisfy all three requirements?

  1. Enforce a screen lock timeout with password required on resume, disable AutoPlay and AutoRun features via Group Policy, and disable the built-in Guest account while disabling or renaming the default Administrator account.Cevap
  2. B
    Enforce a screen saver timeout without password protection, set User Account Control (UAC) to Never Notify, and assign all local users to the local Administrators group.
  3. C
    Configure the Windows Event Viewer to log system events, clear security logs daily to prevent storage exhaustion, and set the built-in Guest account password to expire every 30 days.
  4. D
    Install a physical cable lock on the desktop chassis, attach a privacy screen filter to the monitor, and disable the local Windows Defender Firewall service.

Cevap

Enforce a screen lock timeout with password required on resume, disable AutoPlay and AutoRun features via Group Policy, and disable the built-in Guest account while disabling or renaming the default Administrator account.
The correct option addresses all three security requirements specified in the scenario: enforcing screen lock with password authentication protects unattended sessions, disabling AutoPlay/AutoRun eliminates automated execution vectors from removable drives, and disabling Guest/securing default Administrator accounts hardens local user account baselines.

Adım Adım Çözüm

1
Identify requirement 1: Protecting unattended workstations when staff step away.
Enforcing a screen lock timeout that requires authentication on resume prevents unauthorized users from accessing an active session.
Screen locks enforce session security during temporary absences.
2
Identify requirement 2: Preventing automated malware execution from USB flash drives.
Disabling AutoPlay and AutoRun via Group Policy stops Windows from automatically running scripts or executables when external media is inserted.
AutoRun/AutoPlay disallowance eliminates an automated execution vector.
3
Identify requirement 3: Reducing local account attack surface.
Disabling the Guest account and securing (renaming or disabling) the default Administrator account mitigates account targeting and unauthorized local logon attempts.
Default accounts are well-known targets for brute-force attacks and privilege escalation.

Anahtar Kavram

Workstation Hardening Baselines and Attack Surface Reduction
Bu soruyu puanla