CCFA-200B · Question #76
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best ap
The correct answer is C. Add an allowlist entry for the individual server's IP address. The best approach to updating the Containment Policy to allow a new patch server that should be reachable while hosts in your environment are network contained is to add an allowlist entry for the individual server's IP address. An allowlist entry allows you to define a list of t
Question
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?
Options
- AAdd an allowlist entry for the individual server's MAC address
- BAdd an allowlist entry containing the host group that the server belongs to
- CAdd an allowlist entry for the individual server's IP address
- DAdd an allowlist entry containing CIDR notation for the /24 network the server belongs to
How the community answered
(35 responses)- A6% (2)
- B3% (1)
- C83% (29)
- D9% (3)
Explanation
The best approach to updating the Containment Policy to allow a new patch server that should be reachable while hosts in your environment are network contained is to add an allowlist entry for the individual server's IP address. An allowlist entry allows you to define a list of trusted IP addresses that can communicate with your contained hosts. This way, you can isolate a host from the network while still allowing it to access essential resources or services, such as a patch server. If the server's IP address is static and does not change, adding an individual IP address is more precise and secure than adding a host group or a network range.
Topics
Community Discussion
No community discussion yet for this question.