Soru

Zorluk: ZorPatch and Configuration Management

A security engineer at a utility organization oversees a fleet of distributed industrial edge gateways. Following a vendor firmware patch rollout, a security audit reveals that multiple gateways experienced configuration drift, automatically re-enabling legacy, unencrypted management protocols that violate organizational hardening standards. The engineer must implement a solution that continuously detects non-compliant settings and automatically restores all gateways to their authorized security baseline without manual intervention. Which of the following is the BEST solution to meet these requirements?

  1. Deploy an automated configuration orchestration tool enforcing declarative baseline templates to continuously audit and remediate unauthorized setting changes.Cevap
  2. B
    Implement inline network intrusion prevention system signature rules to filter and drop traffic directed at the unencrypted management protocol ports.
  3. C
    Schedule weekly automated vulnerability assessment scans to generate detective reporting logs for analyst review and manual remediation.
  4. D
    Reconfigure perimeter firewall access control lists to restrict gateway management access strictly to designated jump boxes.

Cevap

Deploying an automated configuration orchestration tool enforcing declarative baseline templates is the best solution because it continuously monitors for configuration drift and automatically restores system settings to the authorized security baseline without manual intervention.
Deploying an automated configuration orchestration tool using declarative baseline templates directly addresses configuration drift. It continuously audits device configurations against the golden baseline standard and automatically enforces compliance by reverting unauthorized setting changes, ensuring endpoints remain hardened without requiring manual intervention.

Adım Adım Çözüm

1
Analyze organizational requirements
Identified the need for continuous configuration drift detection and automated remediation to enforce hardening baselines.
The scenario highlights host-level setting changes resulting from a patch deployment that must be automatically rectified.
2
Evaluate control types for configuration management
Configuration orchestration (such as IaC or configuration management agents) directly maintains system state against baseline templates.
Preventive and compensating network controls (NIPS, firewalls) or periodic detective tools (vulnerability scanners) do not restore local endpoint baselines automatically.
3
Select the optimal solution
Chosen automated configuration orchestration tool enforcing declarative templates.
This fulfills both continuous auditing and automated remediation requirements.

Anahtar Kavram

Configuration Baseline Enforcement and Automated Drift Remediation
Tahmini Süre:2m 0s
Bu soruyu puanla