[Security Architecture]
A security analyst Detected unusual network traffic related to program updating processes The analyst collected artifacts from compromised user workstations. The discovered artifacts were binary files with the same name as existing, valid binaries but. with different hashes which of the following solutions would most likely prevent this situation from reoccurring?
Implementing digital signatures ensures the integrity and authenticity of software binaries. When a binary is digitally signed, any tampering with the file (e.g., replacing it with amalicious version) would invalidate the signature. This allows systems to verify the origin and integrity of binaries before execution, preventing the execution of unauthorized or compromised binaries.
A . Improving patching processes: While important, this does not directly address the issue of verifying the integrity of binaries.
B . Implementing digital signatures: This ensures that only valid, untampered binaries are executed, preventing attackers from substituting legitimate binaries with malicious ones.
C . Performing manual updates via USB ports: This is not practical and does not scale well, especially in large environments.
D . Allowing only files from internal sources: This reduces the risk but does not provide a mechanism to verify the integrity of binaries.
CompTIA Security+ Study Guide
NIST SP 800-57, 'Recommendation for Key Management'
OWASP (Open Web Application Security Project) guidelines on code signing
Cherry
7 months agoRickie
7 months agoDylan
7 months agoWilliam
7 months agoAlica
8 months agoAnnett
8 months agoAmie
8 months agoCyndy
8 months agoValentine
9 months agoFelix
9 months agoAntonio
9 months agoKris
9 months agoHobert
9 months agoPhil
1 year agoTiara
1 year agoLaura
1 year agoGearldine
1 year agoVon
12 months agoFreida
12 months agoRuthann
1 year agoAudry
1 year agoGalen
11 months agoHyun
11 months agoNickolas
11 months agoAlverta
12 months agoGarry
1 year agoIvan
12 months agoElenore
1 year agoCasandra
1 year ago