Soru

Zorluk: OrtaHost, Network, and Architecture Vulnerabilities

An enterprise security team discovers that a bare-metal server's Baseboard Management Controller (BMC) interface running IPMI v2.0 on UDP port 623 is reachable directly from standard workstation VLANs. The IPMI service is configured with Cipher Suite 0, allowing session establishment without authentication and transmitting management traffic in cleartext. Although edge firewalls restrict external internet access to UDP port 623, no internal network segmentation or host-level access control lists exist to restrict internal traffic. Which of the following mitigation strategies BEST addresses the host, protocol, and architectural vulnerabilities described in this scenario?

  1. Disable insecure IPMI cipher suites, enforce encrypted management protocols, and place the BMC interface on an isolated management VLAN with zero-trust access controls.Cevap
  2. B
    Install a web application firewall (WAF) to filter SQL injection payloads directed at UDP port 623 across the workstation subnet.
  3. C
    Rely on the external perimeter edge firewall while reconfiguring internal network switches to inherently trust all workstation VLAN traffic.
  4. D
    Reclassify the IPMI management interface from a preventive control to a detective security control in the host configuration matrix.

Cevap

Disable insecure IPMI cipher suites, enforce encrypted management protocols, and place the BMC interface on an isolated management VLAN with zero-trust access controls.
Disabling weak cipher suites, requiring secure encrypted management protocols, and isolating hardware management interfaces (such as IPMI or BMC) onto a segregated management network directly addresses both host protocol weaknesses and network architectural flaws. Adopting microsegmentation aligns with zero trust principles to prevent lateral movement.

Adım Adım Çözüm

1
Identify host-level protocol weaknesses
IPMI v2.0 with Cipher Suite 0 allows unauthenticated, unencrypted access on UDP port 623.
Legacy or misconfigured management interfaces expose administrative capabilities over cleartext protocols.
2
Identify network architecture weaknesses
Lack of internal VLAN microsegmentation allows direct network access from untrusted workstation subnets to critical hardware management interfaces.
Perimeter firewalls do not protect against internal lateral movement when hosts reside on flat, unsegmented networks.
3
Select comprehensive mitigation controls
Enforce secure protocols (such as TLS or SSH), disable Cipher Suite 0, and isolate management interfaces onto a dedicated, microsegmented VLAN.
Combining host hardening with network isolation fulfills defense-in-depth and zero-trust security requirements.

Anahtar Kavram

Host and Network Architecture Vulnerability Remediation
Bu soruyu puanla