Soru

Zorluk: OrtaMobile Device and Embedded System Security

A network technician is hardening several newly installed, Ethernet-connected embedded digital signage appliances deployed in a public facility. The appliances run a lightweight embedded operating system and receive display content from a central server. Which combination of security controls best protects these embedded systems from local tampering and network compromise?

  1. Disable unused physical ports, change default administrative credentials, and isolate the appliances on a dedicated network VLAN.Cevap
  2. B
    Deploy a Mobile Application Management (MAM) profile to enforce app containerization and selective remote wiping on the display units.
  3. C
    Configure WPA2-Personal with a pre-shared key across all network interfaces on the appliances.
  4. D
    Attach polarized privacy filters to the display screens and install perimeter security bollards around the mounting poles.

Cevap

Disable unused physical ports, change default administrative credentials, and isolate the appliances on a dedicated network VLAN.
Hardening embedded appliances in public areas relies on minimizing the physical and network attack surfaces. Disabling unused physical ports prevents local unauthorized access, changing default management credentials prevents credential-guessing attacks, and placing the devices on an isolated VLAN limits the potential blast radius if a device is compromised.

Adım Adım Çözüm

1
Identify the device category and operational environment.
The target devices are dedicated embedded systems operating in a public area over a wired Ethernet connection.
Embedded appliances often have limited security software capabilities and must be hardened at the system and network infrastructure layers.
2
Determine the appropriate hardening controls for embedded systems.
Restrict local access by disabling unused USB/serial ports and altering factory default passwords; restrict network access by placing devices on an isolated VLAN.
Default credentials and open physical ports are primary attack vectors on public-facing IoT and embedded devices.
3
Evaluate alternative controls to rule out misapplications.
MAM containerization applies to mobile BYOD devices, WPA2 applies to wireless media, and physical screen filters do not secure system software.
Security controls must match the architecture and physical reality of the hardware being protected.

Anahtar Kavram

Embedded System Hardening and Network Segmentation
Bu soruyu puanla