A security engineer is reviewing the results of an annual penetration test. The report lists one of the results as "critical severity" on several domain-joined workstations: SSL/TLS Weak Protocols Supported TLS 1.0, TLS 1.1 Which of the following should the security engineer implement to remediate this finding in the most centralized manner?
- AAn SCCM patch to disable weak protocols in the Schannel hive
- BA GPO to disable weak protocols in the Schannel hive (correct answer)
- CA PowerShell script to disable weak protocols in the HKLM Schannel hive
- DA registry script to disable weak protocols in the Schannel hive
Reveal answer & explanationHide answer
The correct answer is B. Option B: A GPO to disable weak protocols in the Schannel hive This option keeps traffic private / properly secured as required.






