QuestionQ37

Security Architecture

A security architect is onboarding a new EDR agent on servers that traditionally do not have internet access. In order for the agent to receive updates and report back to the management console, some changes must be made. Which of the following should the architect do to best accomplish this requirement?

Choose two
Explanation

A firewall rule permitting the server subnet to reach the internet only through the designated proxy establishes network-layer least privilege, and a proxy policy that allows only the fully qualified domain names the EDR vendor's management portal actually requires limits egress to the minimum needed for updates and console reporting. Opening all of port 443, or filtering only against a known-bad list, would either be too permissive or fail to establish the tightly scoped path an isolated server segment needs.

Community Discussion

No comments yet. Be the first to start the discussion!