To enforce strict endpoint security across a hybrid workforce, a security team is designing a host health validation strategy to enforce configuration baselines and patch management standards. Which of the following technical controls directly ensure that endpoints maintain verified baseline configurations and patch levels? (Select TWO.)
- Deploying configuration management agents to continuously audit workstation settings against established security baselines and automatically remediate configuration driftCevap
- Implementing Network Access Control (NAC) posture assessment to check endpoint operating system patch levels against mandatory patch compliance SLAs before granting network accessCevap
- CPositioning inline perimeter firewalls at network boundaries to block outbound traffic generated by unpatched client software applications
- DDeploying deception honeytokens within local file system directories to automatically trigger OS patch installation upon file access
Cevap
Deploying automated configuration management agents to remediate baseline drift and implementing Network Access Control (NAC) posture assessments to verify patch compliance.
Maintaining secure host states requires verifying both software patch levels and baseline configurations. Automated configuration management agents detect and correct unauthorized setting changes (configuration drift), while posture assessment mechanisms (such as NAC) evaluate patch levels against defined SLAs to ensure non-compliant systems are isolated or updated prior to granting network access.
Adım Adım Çözüm
Anahtar Kavram
Continuous configuration baseline auditing, drift remediation, and endpoint patch compliance validation.