An enterprise security assessment reveals that unprivileged workforce endpoints allow employees to connect unauthorized USB flash drives and execute untrusted software binaries directly from external media. Which of the following host-hardening strategies provides the MOST effective technical control to enforce peripheral hardware restrictions and prevent unauthorized program execution?
- Implement centralized administrative device installation policies paired with endpoint application block rules targeting removable drive locations.Cevap
- BDeploy an inline stateful firewall policy that filters outbound traffic originating from network sockets on ports 80 and 443.
- CMandate that all endpoints establish an encrypted remote-access VPN tunnel prior to reaching enterprise web applications.
- DDeploy network honeypot file shares configured to alert administrators when suspicious executable files are copied across subnets.
Cevap
Implementing centralized administrative device installation policies paired with endpoint application block rules targeting removable drive locations.
The correct answer combines endpoint peripheral control policies with host-based application execution restrictions. Configuring host administrative policies to block USB mass storage class GUIDs prevents the operating system from loading drivers for unauthorized hardware. Additionally, enforcing application control policies prevents execution of binaries from removable drives, mitigating both the physical device risk and the code execution threat.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Device Control and Application Hardening