An administrator observes unauthorized lateral movement via PowerShell Remoting on a Windows network. Which security control best mitigates this risk by restricting administrative access to specific jump hosts?
Trap 1: Disable the Windows Remote Management (WinRM) service globally.
Disabling WinRM globally breaks legitimate administrative workflows and automation scripts. While it stops lateral movement, it is too disruptive for a production environment. Security controls must balance risk reduction with operational functionality by implementing targeted restrictions rather than nuclear options that stop all remote management.
Trap 2: Enable Windows Defender Credential Guard to isolate LSASS.
Credential Guard protects against credential theft by isolating secrets in a virtualized container. While it prevents attackers from dumping memory to steal hashes, it does not restrict the network-level access paths required for PowerShell Remoting. It is a defense-in-depth measure, not a control for movement restriction.
Trap 3: Implement AppLocker in 'Audit Only' mode to track PowerShell usage.
AppLocker in 'Audit Only' mode does not actively block execution; it merely logs activity for review. While useful for visibility, it fails to prevent unauthorized lateral movement as it does not enforce a deny policy. Security controls must be set to 'Enforce' mode to effectively mitigate threats.
- A
Disable the Windows Remote Management (WinRM) service globally.
Why it fails: Disabling WinRM globally breaks legitimate administrative workflows and automation scripts. While it stops lateral movement, it is too disruptive for a production environment. Security controls must balance risk reduction with operational functionality by implementing targeted restrictions rather than nuclear options that stop all remote management.
- B
Enable Windows Defender Credential Guard to isolate LSASS.
Why it fails: Credential Guard protects against credential theft by isolating secrets in a virtualized container. While it prevents attackers from dumping memory to steal hashes, it does not restrict the network-level access paths required for PowerShell Remoting. It is a defense-in-depth measure, not a control for movement restriction.
- C
Configure a WinRM listener to accept connections only from a specific jump host IP.
The WinRM listener configuration allows administrators to define allowed source addresses via the 'IPv4Filter' property. By restricting incoming remote management requests to a hardened jump host, you ensure that even if an attacker gains local admin rights elsewhere, they cannot initiate remote connections to your servers.
- D
Implement AppLocker in 'Audit Only' mode to track PowerShell usage.
Why it fails: AppLocker in 'Audit Only' mode does not actively block execution; it merely logs activity for review. While useful for visibility, it fails to prevent unauthorized lateral movement as it does not enforce a deny policy. Security controls must be set to 'Enforce' mode to effectively mitigate threats.