問題文
The same three measures are recommended for plant controllers and for unmanaged building devices. Which option correctly identifies those measures and the reason they apply to both?
選択肢
- Identify what each device is, narrow what may reach it, and watch what it communicates, because in both cases nothing can be installed on the device itself.
- Install an agent, apply the standard patch cycle, and require a second authentication factor, because both classes of device run an operating system that is able to support all three of these measures once it has been brought under central management.
- Move the devices to a separate physical network and take no further measures, because a separate network that nothing else can reach cannot carry an attack to them.
- Encrypt the device storage, rotate its credentials, and record its logs centrally, because both classes of device hold data that has to be protected where it sits.