Question 1
A security architect at a financial institution is designing a policy for VMware Carbon Black App Control to protect critical database servers. The primary goal is to prevent any unauthorized executables from running, while minimizing administrative overhead for patching cycles managed by an automated deployment tool. The deployment tool's agent is known to use dynamically named executables in temporary directories. Which enforcement level is the most appropriate for these servers?
Answer and explanation
Correct answer: D
High Enforcement is the correct security posture for critical servers, as it blocks all unapproved executables by default. However, to accommodate the automated deployment tool that uses dynamic executables, a specific rule must be created. An updatable trust rule or a rule targeting the deployment tool's trusted publisher certificate would allow the patching process to function without compromising the overall security level. Simply using High Enforcement would block the tool, while Medium or Low Enforcement would not provide adequate protection.