A systems administrator is provisioning standalone Android-based digital signage kiosks deployed in public transit stations. The administrator needs to protect these embedded endpoints against unauthorized software installation, interface tampering, and OS-level access by members of the public. Which TWO of the following security configurations should be implemented to best harden these devices?
- Enforce application whitelisting and enable a single-app kiosk mode profile to restrict navigation.Cevap
- Disable hardware interface options such as USB debugging and restrict firmware access with administrative credentials.Cevap
- CConfigure all kiosks to connect to an open wireless network using WPA2-Personal with shared pre-shared keys.
- DInstall physical bollards and privacy filters around the kiosks to prevent remote network exploit attempts.
Cevap
The administrator should enforce application whitelisting with kiosk mode and disable USB debugging while securing firmware access.
Hardening embedded kiosks requires restricting the software layer through application whitelisting and kiosk mode profiles, alongside locking down physical debugging interfaces like USB debugging and securing bootloader/firmware settings.
Adım Adım Çözüm
Anahtar Kavram
Embedded System and Kiosk Device Hardening Controls