CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A security analyst is reviewing a vulnerability scan report for a database server. The report flags a high-severity vulnerability (CVSS Base Score 8.5) related to an outdated version of the database software. The analyst confirms the vulnerability is legitimate. However, the database server is part of a legacy system that cannot be upgraded without significant re-engineering and downtime, estimated to take several months. What is the MOST appropriate immediate mitigation strategy for this vulnerability?

  1. ATemporarily shut down the database server until the upgrade can be performed.
  2. BImplement a compensating control, such as network segmentation and WAF rules.
  3. CAccept the risk and schedule a re-engineering project for next fiscal year.
  4. DImmediately schedule the database upgrade, accepting the re-engineering and downtime.
Show answer & explanation

Correct answer: B. Implement a compensating control, such as network segmentation and WAF rules.

Given the high severity of the vulnerability and the impracticality of immediate patching/upgrading, the most appropriate immediate mitigation is to implement compensating controls. Network segmentation would restrict access to the vulnerable service, and WAF rules could inspect and block malicious traffic targeting the database, thereby reducing the risk until a permanent solution can be implemented.

Why the other options are wrong

  • A. Shutting down a production database server is a drastic measure that would likely cause significant business disruption and is usually a last resort, not an 'appropriate immediate mitigation' unless the risk of compromise is extremely high and imminent.
  • C. Accepting a high-severity risk without any immediate mitigation is generally not advisable.
  • D. While a permanent upgrade is needed, 'immediately scheduling' a multi-month re-engineering project and downtime is not an 'immediate mitigation strategy'.

Compensating Control

A security control that reduces the risk of a threat when it is impractical or impossible to implement a primary control or fix a vulnerability directly.

  • Acts as an alternative safeguard.
  • Used when direct remediation is not feasible or temporary.
  • Examples include network segmentation, WAFs, IDS/IPS, strong monitoring.

Memory trick: Patch, Compensate, Retire – Don't let vulnerabilities linger, or the fires will higher!

More Vulnerability Management questions