CAS-001 · Question #295
An administrator has a system hardening policy to only allow network access to certain services, to always use similar hardware, and to protect from unauthorized application configuration changes…
The correct answer is D. Virtualization E. Host firewall. The policy has three requirements: (1) restrict network access to specific services, (2) standardize hardware, and (3) prevent unauthorized configuration changes. A host-based firewall (E) directly enforces which services are accessible over the network on each individual host…
Question
An administrator has a system hardening policy to only allow network access to certain services, to always use similar hardware, and to protect from unauthorized application configuration changes. Which of the following technologies would help meet this policy requirement? (Select TWO).
Options
- ASpam filter
- BSolid state drives
- CManagement interface
- DVirtualization
- EHost firewall
How the community answered
(22 responses)- A5% (1)
- B5% (1)
- C14% (3)
- D77% (17)
Explanation
The policy has three requirements: (1) restrict network access to specific services, (2) standardize hardware, and (3) prevent unauthorized configuration changes. A host-based firewall (E) directly enforces which services are accessible over the network on each individual host, satisfying requirement 1. Virtualization (D) satisfies requirements 2 and 3: it enables consistent, templated virtual machine images ensuring identical 'hardware' (virtual hardware) across deployments, and snapshots/immutable images can be used to detect or revert unauthorized configuration changes. Options A (spam filter) and B (SSDs) are irrelevant to network access control or configuration integrity. Option C (management interface) could assist with administration but does not inherently enforce the stated policy requirements on its own.
Topics
Community Discussion
No community discussion yet for this question.