An organization's security operations center observes that newly provisioned virtual servers in a public cloud environment consistently lack mandatory security monitoring agents and feature non-standard firewall configurations. An investigation reveals that system administrators are manually launching instances from legacy local image templates instead of using approved central images. Which of the following operational practices should the organization implement to MOST effectively prevent future configuration drift?
- AApplying host-based firewall rules to restrict remote management access to the virtual servers
- Enforcing automated deployment pipelines that instantiate virtual machines exclusively from version-controlled Infrastructure as Code (IaC) baseline templatesCevap
- CScheduling monthly manual compliance reviews to identify and remediate baseline deviations across virtual instances
- DIsolating the cloud management console using dedicated virtual private network (VPN) tunnels
Cevap
Enforcing automated deployment pipelines that instantiate virtual machines exclusively from version-controlled Infrastructure as Code (IaC) baseline templates
Automating virtual machine provisioning through version-controlled Infrastructure as Code (IaC) templates ensures that all new cloud instances adhere to predefined, tested security baselines and automatically include required monitoring agents upon deployment.
Adım Adım Çözüm
Anahtar Kavram
Patch and Configuration Management