CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A legacy medical device running an unsupported operating system has a critical unpatched vulnerability. The vendor states that applying any OS patch will void the device's regulatory certification. Which action best mitigates the risk while keeping the device certified?
- AUninstall the operating system and replace it with a patched version
- BIgnore the vulnerability since patching is not possible
- CDisable all logging on the device to reduce its attack surface
- DIsolate the device on a segmented VLAN with strict firewall rules limiting access
Show answer & explanationAnswer & explanation
Correct answer: D. Isolate the device on a segmented VLAN with strict firewall rules limiting access
When a vulnerability cannot be directly patched due to certification or vendor constraints, a compensating control such as network segmentation and strict access control reduces exposure and risk without altering the device itself.
Why the other options are wrong
- A. Replacing the OS would void certification, which the vendor has stated is not acceptable.
- B. Ignoring the vulnerability leaves the organization exposed and is not an acceptable risk response.
- C. Disabling logging reduces visibility and does not mitigate the underlying vulnerability.
Compensating Control
An alternative security measure implemented when the primary/direct fix (like patching) is not feasible, reducing risk to an acceptable level.
- Common for legacy/unsupported systems
- Examples: network segmentation, ACLs, enhanced monitoring
- Should be documented as part of risk acceptance/exception process
Memory trick: Can't patch it? Fence it off instead.