During a security posture review of a enterprise cloud infrastructure, an audit reveals that newly provisioned virtual machine instances frequently drift from established secure configuration baselines over time due to manual administrator modifications and unapproved emergency changes. Which enterprise hardening practice provides the MOST effective mechanism to continuously prevent and remediate host baseline configuration drift across all deployed instances?
- ADeploying stateful network firewalls and perimeter intrusion prevention systems at the cloud tenant ingress boundary
- Implementing Infrastructure as Code with automated configuration management tooling to enforce continuous baseline complianceCevap
- CDeploying deception decoys and high-interaction honeypots within host management subnets to capture unauthorized modifications
- DReclassifying host baseline configuration guides from technical preventive controls to operational deterrent controls
Cevap
Implementing Infrastructure as Code with automated configuration management tooling to enforce continuous baseline compliance is the most effective mitigation strategy.
The selection recommending Infrastructure as Code paired with automated configuration management is correct because declarative configuration tools continuously monitor system state against standardized security baselines and automatically revert unauthorized changes, effectively neutralizing configuration drift.
Adım Adım Çözüm
Anahtar Kavram
Configuration Drift Remediation and Continuous Enforcement via Automated Configuration Management