CompTIA SecurityX (CAS-005)Security OperationsMedium
During a routine vulnerability scan of an organization's network, a security professional discovers several unpatched systems running end-of-life operating systems. These systems host critical legacy applications that cannot be easily updated or replaced due to compatibility issues and vendor support. What is the most appropriate long-term mitigation strategy for these systems?
- ASchedule regular reboots of the systems to clear transient malware.
- BImplement host-based firewalls on each system to restrict traffic.
- CIsolate the systems into a dedicated network segment with strict access controls.
- DApply intrusion detection/prevention systems (IDPS) at the perimeter.
Show answer & explanationAnswer & explanation
Correct answer: C. Isolate the systems into a dedicated network segment with strict access controls.
Isolating end-of-life systems with critical applications into a dedicated network segment (e.g., a DMZ or air-gapped network) and applying strict access controls is the most effective long-term mitigation. This reduces their exposure to the broader network and potential threats while maintaining their operational status.
Why the other options are wrong
- A. Regular reboots might clear some transient malware but do not address the underlying vulnerabilities of the end-of-life operating systems.
- B. Host-based firewalls offer some protection but may not be sufficient for unpatched EOL systems, as OS vulnerabilities could bypass them.
- D. Perimeter IDPS is important but insufficient for internal EOL systems; it doesn't protect against internal threats or advanced persistent threats that bypass the perimeter.
Network Segmentation
The practice of dividing a computer network into multiple smaller network segments or subnets, often to improve security, performance, and manageability.
- Limits lateral movement of attackers.
- Contains breaches to smaller areas.
- Enables granular access control policies.
Memory trick: Old systems need a strong, isolated castle.