Soru

Zorluk: Çok zorPatch and Configuration Management

A security operations team discovers that critical production servers frequently experience configuration drift due to uncoordinated hotfixes applied by system administrators during emergency outage incidents. Although automated configuration auditing tools successfully flag these non-compliant system states during nightly scans, security engineers cannot readily distinguish between unauthorized vulnerabilities and approved emergency hotfixes. Which of the following solutions should the security team implement to effectively manage configuration drift while maintaining audit compliance for emergency changes?

  1. Integrate automated configuration management systems with the service management database to dynamically reconcile live endpoint baseline scans against authorized emergency change requests.Cevap
  2. B
    Deploy compensating network firewall rules to automatically isolate drifted servers into a quarantined VLAN until all manual hotfixes can be reviewed during scheduled maintenance windows.
  3. C
    Reclassify the automated configuration auditing scanner as a preventive control by authorizing its local host agent to immediately terminate unverified system processes upon detection.
  4. D
    Reassign technical baseline modification and approval authority from business application owners to system administrators who apply emergency patches.

Cevap

Integrate automated configuration management systems with the service management database to dynamically reconcile live endpoint baseline scans against authorized emergency change requests.
Integrating automated configuration monitoring tools with the service management database (CMDB) bridges the gap between technical drift detection and administrative change management. When an emergency hotfix alters a server baseline, the configuration management tool checks the CMDB for a corresponding approved emergency change ticket. If a valid ticket exists, the baseline variation is recognized as authorized drift; if no ticket exists, it is treated as unauthorized configuration drift requiring remediation.

Adım Adım Çözüm

1
Analyze the operational problem
Identify that the core issue is an inability to correlate live configuration drift with legitimate emergency change documentation.
Security operations need continuous automated verification without breaking emergency change management workflows.
2
Evaluate patch and configuration management governance
Determine that linking configuration assessment tools with formal IT service management (ITSM/CMDB) tracking enables real-time verification of baseline exceptions.
Automated reconciliation ensures unauthorized drift is highlighted for remediation while authorized emergency hotfixes are automatically reconciled against open change tickets.
3
Differentiate governance roles and control functions
Reject responses that misclassify control categories (detective vs. preventive), misapply network mitigations to system states, or break role separation.
Maintaining proper security control classification and role boundaries is critical for enterprise security posture.

Anahtar Kavram

Configuration Drift and Automated Baseline Reconciliation
Bu soruyu puanla