The data center is fully air-gapped and outbound connections are forbidden, yet vendor support will need diagnostic data someday. What access pattern is the sanctioned one for such a locked-down site?
Select an answer to reveal the explanation.
Short Explanation
An air gap forbids open doors, not support. The gap-safe pattern keeps you holding the door: the collector runs from inside, you inspect the bundle, you hand it across — and if a live session is ever truly needed, it's brokered, time-boxed, and revocable by you. Standing holes to the outside? Not in this building.
Full Explanation
Locked-down sites still purchase support; what changes is who controls the door. The sanctioned pattern is locally initiated, locally reversible support access: the appliance's own collector is run by authorized staff from inside the perimeter, producing a bounded support bundle the site can inspect before it is handed over through approved channels — and when a live vendor session is genuinely needed, it is brokered and revocable, opened from inside, time-boxed, and terminated by the site at will, so the security posture never depends on a standing exception. A permanent inbound support port fails twice: inbound doors into a sealed fabric invert the entire air-gap model, and permanent exceptions are exactly the weakness adversaries inventory first. Denying any support path fails the requirement without honoring it — local log analysis is one component of the gap model, not an answer to the day expert diagnostics are needed. Egress whitelisting of the vendor's address space fails on definition: an air gap is defined by the absence of routed paths outward, and a NAT rule to the vendor re-establishes precisely the route the gap exists to deny. Exam caveat: the exam contrasts locally initiated and revocable against standing openings — the former is always the answer. Operational check: document the collector runbook — who runs it, where the bundle is inspected, how it is transferred — and rehearse one dry run before handover.