Soru

Zorluk: Çok zorMitigation Strategies and Enterprise Hardening Practices

An enterprise security architect is designing compensating controls for legacy operational technology (OT) controllers on an industrial network. The controllers run an end-of-life operating system that cannot be patched or upgraded due to critical vendor warranty constraints. Which TWO of the following technical mitigation techniques should the security architect implement to prevent privilege escalation and lateral movement without impacting system stability? (Select TWO.)

  1. Implement application allowlisting policies on the host controllers to restrict execution strictly to pre-approved operational binaries and scripts.Cevap
  2. Isolate the host controllers within microsegmented network zones using firewalls to limit communications strictly to essential industrial protocols.Cevap
  3. C
    Deploy inline deceptive honeypot software directly on host controllers to intercept and inspect incoming industrial control packets in real time.
  4. D
    Enforce strict perimeter firewall boundaries around the enterprise while trusting all internal network communication between internal operational subnets.

Cevap

The correct mitigations are implementing application allowlisting on host controllers and isolating the controllers within microsegmented network zones using firewalls.
Application allowlisting and microsegmentation provide robust compensating controls for legacy environments where patching is impossible. Application allowlisting prevents malicious code from running locally to escalate privileges, while microsegmentation restricts lateral movement by limiting network communications strictly to required operational protocols.

Adım Adım Çözüm

1
Analyze host constraints and vulnerability risks
Patching is not viable due to legacy OS limitations and vendor warranties, requiring host-based compensating controls that block unauthorized binary execution.
Host security must prevent exploit execution without altering legacy application software.
2
Select execution control mitigation
Application allowlisting ensures only explicitly approved binaries and scripts are permitted to execute.
Allowlisting prevents privilege escalation tools and dropped payloads from running even if vulnerability vectors exist.
3
Select network containment mitigation
Microsegmentation enforces network layer isolation around host controllers.
Restricting communications strictly to necessary industrial control protocols stops lateral movement across network segments.

Anahtar Kavram

Enterprise Hardening and Compensating Security Controls for Legacy Systems
Bu soruyu puanla