A security analyst is establishing a patch and configuration management procedure for an air-gapped Industrial Control System (ICS) network following the disclosure of a critical firmware vulnerability. Which of the following technical controls and procedural steps should the analyst execute to ensure safe patch deployment and maintain system baselines? (Select TWO.)
- Validate patches in an isolated staging environment using offline installation media verified with cryptographic hashes prior to deployment.Cevap
- BDeploy perimeter firewalls as a corrective security control to substitute for performing software and firmware updates on vulnerable devices.
- Archive verified offline baseline configuration backups and maintain documented roll-back plans for all managed controllers before executing updates.Cevap
- DConfigure continuous cloud-based automated configuration remediation agents to dynamically pull vendor patches over public networks.
Cevap
The correct procedures are validating patches in an isolated staging environment using cryptographically verified offline media, and archiving verified offline baseline configuration backups with documented roll-back plans prior to update execution.
In air-gapped industrial environments, patch and configuration management requires verifying file integrity via cryptographic hashes, testing updates in a staging environment prior to production release, and securing baseline configurations with tested roll-back mechanisms to ensure high availability and prevent unexpected system outages.
Adım Adım Çözüm
Anahtar Kavram
Air-gapped Patch and Configuration Management Lifecycle