CAS-003 · Question #479
A company is migrating systems from an on-premises facility to a third-party managed datacenter. For continuity of operations and business agility, remote access to all hardware platforms must be…
The correct answer is A. Integrated platform management interfaces are configured to allow access only via SSH C. Access is captured in event logs that include source address, time stamp, and outcome. The two requirements are robust remote access to hardware platforms and a detailed audit trail. Configuring Integrated Platform Management Interfaces (IPMI, iDRAC, iLO) to allow access only via SSH (A) satisfies the remote access requirement with strong encryption and…
Question
A company is migrating systems from an on-premises facility to a third-party managed datacenter. For continuity of operations and business agility, remote access to all hardware platforms must be available at all times. Access controls need to be very robust and provide an audit trail. Which of the following security controls will meet the company's objectives? (Select two.)
Options
- AIntegrated platform management interfaces are configured to allow access only via SSH
- BAccess to hardware platforms is restricted to the systems administrator's IP address
- CAccess is captured in event logs that include source address, time stamp, and outcome
- DThe IP addresses of server management interfaces are located within the company's extranet
- EAccess is limited to interactive logins on the VDi
- FApplication logs are hashed cryptographically and sent to the SIEM
How the community answered
(40 responses)- A73% (29)
- B5% (2)
- D15% (6)
- F8% (3)
Explanation
The two requirements are robust remote access to hardware platforms and a detailed audit trail. Configuring Integrated Platform Management Interfaces (IPMI, iDRAC, iLO) to allow access only via SSH (A) satisfies the remote access requirement with strong encryption and authentication, replacing insecure protocols like Telnet. Capturing access in event logs that include source address, timestamp, and outcome (C) directly provides the audit trail the organization needs. Restricting access to a single IP (B) breaks the 'available at all times' and 'business agility' requirements. Placing interfaces in the extranet (D) improves availability but does not enforce robust access controls on its own. VDI-only logins (E) are too restrictive. Hashing logs and sending to a SIEM (F) improves log integrity but is not an access control and does not fulfill the primary objectives.
Topics
Community Discussion
No community discussion yet for this question.