An enterprise security analyst discovers that routine software vendor patches regularly overwrite customized security hardening settings on production Linux servers, resetting critical system configurations to insecure defaults. Which of the following patch and configuration management solutions best prevents configuration drift while ensuring ongoing security baseline compliance after patch deployment?
- Deploying an automated configuration management tool with scheduled enforcement playbooksCevap
- BInstalling a network intrusion prevention system (NIPS) to detect unauthorized configuration changes in real time
- CScheduling post-patch manual vulnerability assessments to review system configurations quarterly
- DConfiguring file system access permissions to deny read-write access to the root service account
Cevap
Deploying an automated configuration management tool with scheduled enforcement playbooks
Automated configuration management platforms utilize infrastructure code or playbooks to continuously audit system configurations and automatically re-enforce security baselines whenever a patch or administrator alters setting parameters.
Adım Adım Çözüm
Anahtar Kavram
Configuration Baseline Enforcement and Drift Remediation
Tahmini Süre:1m 15s