CompTIA SecurityX (CAS-005)Security OperationsMedium

During a routine vulnerability scan of an organization's network, a security professional discovers several unpatched systems running end-of-life operating systems. These systems host critical legacy applications that cannot be easily updated or replaced due to compatibility issues and vendor support. What is the most appropriate long-term mitigation strategy for these systems?

  1. ASchedule regular reboots of the systems to clear transient malware.
  2. BImplement host-based firewalls on each system to restrict traffic.
  3. CIsolate the systems into a dedicated network segment with strict access controls.
  4. DApply intrusion detection/prevention systems (IDPS) at the perimeter.
Show answer & explanation

Correct answer: C. Isolate the systems into a dedicated network segment with strict access controls.

Isolating end-of-life systems with critical applications into a dedicated network segment (e.g., a DMZ or air-gapped network) and applying strict access controls is the most effective long-term mitigation. This reduces their exposure to the broader network and potential threats while maintaining their operational status.

Why the other options are wrong

  • A. Regular reboots might clear some transient malware but do not address the underlying vulnerabilities of the end-of-life operating systems.
  • B. Host-based firewalls offer some protection but may not be sufficient for unpatched EOL systems, as OS vulnerabilities could bypass them.
  • D. Perimeter IDPS is important but insufficient for internal EOL systems; it doesn't protect against internal threats or advanced persistent threats that bypass the perimeter.

Network Segmentation

The practice of dividing a computer network into multiple smaller network segments or subnets, often to improve security, performance, and manageability.

  • Limits lateral movement of attackers.
  • Contains breaches to smaller areas.
  • Enables granular access control policies.

Memory trick: Old systems need a strong, isolated castle.

More Security Operations questions