A secure data center forbids all outbound internet connections. During network configuration the engineer finds a pre-populated NTP entry pointing at a public internet time pool and leaves it in place. The security audit flags it. What is the correct approach to time sources in this environment?
Select an answer to reveal the explanation.
Short Explanation
Your appliance should take time from the source the site designated as authoritative — and in a building with no outbound doors, an internet pool will never be it. Worse, it fails so quietly that nobody ever rechecks the setting that came pre-filled. Point it at the permitted internal servers, then verify the sync actually happened; a configured time source without synchronization is just typing.
Full Explanation
An infrastructure device draws its time from whatever the site design designates as authoritative and permitted by security policy — in a data center that forbids outbound traffic, that is the customer's internal NTP infrastructure, not a public internet pool that happened to ship in a configuration template. Leaving the pool entry silently creates an egress dependency the firewall will never satisfy: synchronization fails, drift accumulates, and no alarm fires on a setting nobody revisited because it looked factory-intended. Raising the poll interval fails on policy rather than arithmetic — a prohibited path is prohibited at one packet, and the audit finding is about the path's existence, not its bandwidth. Manual time with no synchronization fails on consequences: certificate validation, event correlation across systems, and job schedules all depend on agreed time, so an intentionally drifting clock is a broken clock by policy. Making the storage appliance the site reference inverts the source-of-truth hierarchy — the appliance is a time consumer inside the customer's time architecture, not a stratum authority for other systems. Exam caveat: after pointing at internal servers, allow several polls for a source to be selected before declaring success. Operational check: list the configured sources, confirm one is marked synchronized, compare the displayed time to a reference, and record the permitted sources in the deployment documentation.