Soru

Zorluk: ZorPatch and Configuration Management

A security engineer at a financial institution is establishing a patch and configuration management framework for dual-homed payment processing nodes. The environment requires continuous compliance enforcement against baseline images, strict change validation before production deployment, and protection against unauthorized system modifications. Which of the following strategies should the security engineer implement to maintain secure configuration baselines and control patch deployment risks? (Select TWO.)

  1. Utilize automated infrastructure-as-code configuration management tools to continuously audit system state and automatically remediate configuration drift back to approved baselines.Cevap
  2. Staging patch updates in an isolated test environment and verifying cryptographic signature hashes prior to deploying updates into production.Cevap
  3. C
    Deploying network perimeter firewall filtering rules as a permanent substitute for applying critical operating system security patches.
  4. D
    Reclassifying host-based automated audit logging controls as preventive physical security mechanisms to satisfy compliance reporting mandates.

Cevap

The security engineer should utilize automated infrastructure-as-code tools to continuously audit and remediate configuration drift, and stage patch updates in an isolated environment while verifying cryptographic signature hashes before production deployment.
Automated infrastructure-as-code tools continuously validate system settings against established security baselines and automatically remediate configuration drift. Additionally, staging patches in an isolated environment combined with verifying cryptographic signatures prevents unstable or malicious update packages from compromising production systems.

Adım Adım Çözüm

1
Analyze configuration maintenance requirements
Identified the need for continuous drift detection and enforcement using automated configuration baselines.
Manual baseline auditing is ineffective in dynamic environments, making automated remediation via configuration management essential for eliminating drift.
2
Evaluate patch deployment risk mitigation controls
Selected pre-deployment staging and cryptographic hash verification.
Testing patches in staging prevents unexpected service outages, and verifying signature hashes guarantees patch integrity against tampering.
3
Assess distractor validity
Rejected using firewalls as permanent patch replacements and misclassifying control categories.
Firewalls do not remediate system code flaws, and mislabeling control types invalidates risk governance modeling.

Anahtar Kavram

Continuous baseline configuration enforcement and staged patch verification
Bu soruyu puanla