Soru

Zorluk: Çok zorWorkstation Hardening and Best Practices

A system administrator is hardening a fleet of standalone Windows 11 desktops used by shift workers in a medical laboratory. The security compliance baseline requires prohibiting automatic execution of files from removable storage media, disabling unused guest access, and preventing unauthorized observers from viewing previously logged-on usernames at the Windows sign-in screen. During audit testing, inserting a USB flash drive still presents a pop-up menu allowing users to open media files, and the sign-in screen continues to display the username of the last technician who logged in. Which of the following policy configurations should the administrator implement to resolve both compliance issues?

  1. Configure 'Turn off AutoPlay' for all drives in Local Group Policy and enable the Security Setting 'Interactive logon: Do not display last signed-in'.Cevap
  2. B
    Configure 'Disable AutoRun' in the Control Panel Devices applet and set the built-in Administrator account as the default auto-logon profile.
  3. C
    Open Event Viewer to disable the Shell Hardware Detection service and use Task Scheduler to clear the Windows Security log at every sign-out.
  4. D
    Modify the User Accounts applet in Control Panel to turn off User Account Control (UAC) and disable credential caching under Credential Manager.

Cevap

Configure 'Turn off AutoPlay' for all drives in Local Group Policy and enable the Security Setting 'Interactive logon: Do not display last signed-in'.
Configuring 'Turn off AutoPlay' for all drives within Group Policy prevents Windows from displaying execution prompts or automatically running content when removable USB media is inserted. Additionally, configuring the Security Setting 'Interactive logon: Do not display last signed-in' under Local Security Policy prevents the operating system from revealing the account name of the last user who logged in, fulfilling both required hardening controls.

Adım Adım Çözüm

1
Identify the mechanism controlling removable media execution prompts.
AutoPlay handles interactive media prompts and hardware action choices when USB drives are attached.
Setting 'Turn off AutoPlay' for all drives under Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies prevents interactive media prompts.
2
Identify the Local Security Policy controlling sign-in screen username exposure.
The policy 'Interactive logon: Do not display last signed-in' located under Local Policies > Security Options hides the previously logged-in username.
This mitigates shoulder surfing and username harvesting threats on shared shift-work workstations.

Anahtar Kavram

Workstation Hardening Policies (AutoPlay and Interactive Logon Security)
Tahmini Süre:2m 0s
Bu soruyu puanla