Soru

Zorluk: KolayPatch and Configuration Management

An enterprise security policy requires that any unauthorized changes to server system configurations are automatically detected and restored to a pre-approved security state. Which of the following operational controls best meets this requirement?

  1. Automated configuration management baseline enforcementCevap
  2. B
    Centralized SIEM security audit log retention
  3. C
    Host-based firewall traffic filtering rules
  4. D
    Scheduled manual patch deployment procedures

Cevap

Automated configuration management baseline enforcement
Automated configuration management baseline enforcement continuously compares system settings against an established baseline and automatically remediates configuration drift by restoring approved settings.

Adım Adım Çözüm

1
Identify the core requirement in the scenario.
The scenario requires automatic detection and restoration of unauthorized system configuration changes (configuration drift).
Security baselines define approved operational settings, and automated tools enforce compliance against these baselines continuously.
2
Evaluate the technical capabilities of available operational controls.
Automated configuration management tools actively monitor settings and enforce baselines, reverting unauthorized drift automatically without manual intervention.
Other control options act as detective logging mechanisms or network filters rather than internal system configuration enforcement tools.

Anahtar Kavram

Configuration Drift and Automated Baseline Enforcement
Bu soruyu puanla