Soru

Zorluk: OrtaWorkstation Hardening and Best Practices

A systems specialist is preparing a batch of Windows 11 desktop computers designated for a corporate financial analysis unit handling restricted client data. The goal is to reduce the attack surface and prevent unauthorized physical or administrative access. Which of the following steps should the specialist execute to properly harden these workstations? (Select TWO.)

  1. Disable the built-in Guest account and rename the local Administrator account.Cevap
  2. Configure a mandatory screen saver lock policy requiring password authentication upon resume.Cevap
  3. C
    Enable the default Guest account to allow external auditors quick local logon privileges without credential provisioning.
  4. D
    Install physical privacy filters on monitors as a primary control to stop unauthorized entry tailgating.

Cevap

The specialist should disable the built-in Guest account while renaming the local Administrator account, and configure a mandatory screen saver lock policy requiring password authentication upon resume.
Hardening workstations involves eliminating unnecessary account vectors (such as disabling the Guest account and renaming the default Administrator account) and mitigating physical exposure through unattended session controls (such as screen saver locks requiring password authentication).

Adım Adım Çözüm

1
Identify default account vulnerabilities and account hardening controls.
Disabling the Guest account and renaming the default Administrator account reduces vector exposure to automated brute-force attacks.
Standard account names are well-known targets for malicious actors.
2
Identify session security and idle timeout requirements.
Configuring a screen saver lock secures unattended workstations against unauthorized physical interaction.
Workstations left unattended present an immediate security risk if session lock policies are not active.

Anahtar Kavram

Workstation Hardening and Attack Surface Reduction
Bu soruyu puanla