Soru

Zorluk: OrtaMitigation Strategies and Enterprise Hardening Practices

An enterprise security audit reveals that workstations in a software development subnet can establish direct, unmonitored SSH and remote execution sessions to production database servers without passing through a centralized management gateway. Which of the following mitigation strategies should the security team implement FIRST to enforce strict administrative boundary isolation and prevent unauthorized lateral movement?

  1. Enforce microsegmentation policies requiring all administrative access to originate from designated jump servers protected by multi-factor authenticationCevap
  2. B
    Deploy an inline network intrusion prevention system at the enterprise egress firewall to monitor outbound SSH traffic
  3. C
    Deploy file integrity monitoring tools across production database servers to generate real-time alerts on system file modifications
  4. D
    Configure deception honeypots within the developer subnet to capture unauthorized credentials used during lateral movement attempts

Cevap

Enforce microsegmentation policies requiring all administrative access to originate from designated jump servers protected by multi-factor authentication.
Enforcing microsegmentation along with jump servers and mandatory multi-factor authentication directly restricts network pathways and verifies identity before granting administrative access to sensitive production database servers. This preventive control establishes strict administrative boundary isolation and halts lateral movement.

Adım Adım Çözüm

1
Analyze the security audit finding
Direct network access from workstation endpoints to production database subnets exposes critical infrastructure to lateral movement without centralized access control or MFA enforcement.
Identifying the network architecture vulnerability is necessary to select an appropriate preventive security control.
2
Evaluate mitigation controls for lateral movement prevention
Restricting network traffic via microsegmentation rules and funneling administrative access through secure jump servers requires explicit authorization and multi-factor authentication.
Enterprise hardening mandates limiting east-west network traffic and establishing secure management pathways.
3
Select the primary preventive mitigation strategy
Microsegmentation paired with secure jump servers directly eliminates direct endpoint-to-database connections.
Preventive access isolation effectively secures administrative boundaries across distinct enterprise network zones.

Anahtar Kavram

Enterprise Hardening and Microsegmentation
Bu soruyu puanla