CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is reviewing a vulnerability scan report that lists several critical findings. One finding indicates that an internal web server is running an outdated version of Apache HTTP Server (2.2.x) which is known to have multiple unpatched vulnerabilities. The server cannot be immediately updated due to application compatibility issues. To mitigate the risk, the team implements a Web Application Firewall (WAF) in front of the server, configured with rules to detect and block exploit attempts targeting the known Apache vulnerabilities. What type of control does the WAF represent in this scenario?
- APreventative Control
- BDetective Control
- CCompensating Control
- DCorrective Control
Show answer & explanationAnswer & explanation
Correct answer: C. Compensating Control
A compensating control is an alternative security measure that is put in place to satisfy a requirement that cannot be met directly by the primary control. In this case, patching (the primary control) cannot be done, so the WAF acts as a compensating control to reduce the risk associated with the unpatched vulnerabilities.
Why the other options are wrong
- A. A preventative control aims to stop an incident from occurring. While the WAF is preventative in nature, the question specifically asks about its role in mitigating a vulnerability that cannot be directly fixed, pointing to it as a compensating measure.
- B. A detective control aims to identify an incident after it has occurred. While WAFs can have detective capabilities, its primary role here is to block exploit attempts, which is a preventative action, specifically compensating for a missed primary control.
- D. A corrective control aims to restore systems to normal after an incident, which is not the role of the WAF here.
Compensating Control
A compensating control is an alternative security measure used to meet a security requirement when the primary control cannot be fully implemented or is deemed impractical.
- It does not directly fix the underlying vulnerability but reduces its associated risk.
- Often used for legacy systems, unpatchable software, or specific environmental constraints.
- Examples include WAFs for unpatched web apps, network segmentation for vulnerable devices, or enhanced monitoring.
Memory trick: PDC-A: Prevent, Detect, Correct, Compensate – all types of controls.