CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy

A legacy medical device running an unsupported operating system has a critical unpatched vulnerability. The vendor states that applying any OS patch will void the device's regulatory certification. Which action best mitigates the risk while keeping the device certified?

  1. AUninstall the operating system and replace it with a patched version
  2. BIgnore the vulnerability since patching is not possible
  3. CDisable all logging on the device to reduce its attack surface
  4. DIsolate the device on a segmented VLAN with strict firewall rules limiting access
Show answer & explanation

Correct answer: D. Isolate the device on a segmented VLAN with strict firewall rules limiting access

When a vulnerability cannot be directly patched due to certification or vendor constraints, a compensating control such as network segmentation and strict access control reduces exposure and risk without altering the device itself.

Why the other options are wrong

  • A. Replacing the OS would void certification, which the vendor has stated is not acceptable.
  • B. Ignoring the vulnerability leaves the organization exposed and is not an acceptable risk response.
  • C. Disabling logging reduces visibility and does not mitigate the underlying vulnerability.

Compensating Control

An alternative security measure implemented when the primary/direct fix (like patching) is not feasible, reducing risk to an acceptable level.

  • Common for legacy/unsupported systems
  • Examples: network segmentation, ACLs, enhanced monitoring
  • Should be documented as part of risk acceptance/exception process

Memory trick: Can't patch it? Fence it off instead.

More Vulnerability Management questions