The correct answer is to prevent configuration drift and unauthorized changes. Immutable infrastructure improves security by preventing configuration drift and unauthorized changes to production systems. Rather than modifying existing systems (which can lead to inconsistencies and security issues), immutable infrastructure requires replacing entire systems when changes are needed, ensuring systems always match their known secure baseline. This approach ensures that all systems are in a known, verified state and reduces the risk of unauthorized or undocumented changes compromising security.
To ensure consistent security controls across all environments is incorrect because while immutable infrastructure can contribute to consistency, its primary purpose is specifically about preventing changes to deployed systems rather than ensuring identical controls across different environments. Environment consistency is typically addressed through infrastructure as code and deployment pipelines rather than immutability itself.
To establish verifiable deployment artifacts for compliance audits is incorrect because while immutable infrastructure can create better auditability as a side benefit, this is not its primary purpose. The primary security benefit comes from preventing unauthorized runtime changes rather than creating verifiable artifacts. Audit requirements are typically addressed through separate logging, monitoring, and documentation processes.
To implement zero-trust architecture principles in cloud environments is incorrect because while immutable infrastructure can support zero-trust models, they are distinct security concepts. Zero-trust focuses on eliminating implicit trust and requiring verification for all access, while immutability focuses on preventing changes to deployed systems. Immutable infrastructure is not required for implementing zero-trust architecture, nor does it inherently create a zero-trust environment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is configuration drift in the context of infrastructure?
Open an interactive chat with Bash
How does immutable infrastructure enhance security?
Open an interactive chat with Bash
What role does infrastructure as code (IaC) play in maintaining immutable infrastructure?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access