A network technician is installing smart environmental monitoring sensors throughout a corporate data center. These embedded IoT devices run a lightweight, proprietary firmware that cannot support endpoint security software or Mobile Device Management (MDM) agent enrollment. Which of the following strategies best secures these embedded devices against unauthorized access while protecting the internal network?
- Place the embedded sensors on a dedicated, logically isolated VLAN with restricted firewall rules.Cevap
- BForce the devices to enroll in the enterprise MDM portal to enforce full-device encryption policies.
- CConnect all sensors to the primary internal Wi-Fi network using WPA2-Personal with a shared passphrase.
- DInstall physical tamper-evident enclosures on the sensors while leaving them on the main broadcast domain.
Cevap
Placing the embedded sensors on a dedicated, logically isolated VLAN with restricted firewall rules is the best security approach.
Embedded systems and IoT devices frequently run restricted or proprietary operating systems that cannot support agent-based endpoint security software or MDM management. The industry standard approach for securing these devices is network segmentation (such as placing them on a dedicated VLAN) paired with restrictive firewall access control lists (ACLs) to ensure they cannot initiate unauthorized communication with internal corporate assets.
Adım Adım Çözüm
Anahtar Kavram
Embedded System Security & Network Isolation