Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security analyst is conducting a vulnerability assessment of an internal web application. They discover that the application is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization. The development team states they cannot immediately fix the code. Which of the following is the most effective compensating control to implement for this vulnerability until a code fix can be deployed?

  1. ABlock all external network access to the application.
  2. BUpgrade the underlying web server software.
  3. CDisable JavaScript execution in all user browsers.
  4. DImplement a Web Application Firewall (WAF) to filter malicious input.
Show answer & explanation

Correct answer: D. Implement a Web Application Firewall (WAF) to filter malicious input.

Disabling JavaScript (B) is impractical and would break most web applications. Upgrading the web server (C) is unlikely to directly address an application-level XSS vulnerability. Blocking all external access (D) would make the application unusable. A Web Application Firewall (WAF) (A) is specifically designed to inspect and filter HTTP traffic, making it an effective compensating control to detect and block XSS attempts by sanitizing or blocking malicious input before it reaches the vulnerable application.

Why the other options are wrong

  • A. Blocking all external access renders the web application unusable, which is not a practical solution.
  • B. Upgrading the web server addresses server-level vulnerabilities, not typically application-level XSS flaws.
  • C. Disabling JavaScript is not a feasible solution for most modern web applications and would severely impact functionality.

Compensating Control

A security control implemented to satisfy the requirements of a security measure that cannot be met due to technical or business constraints, providing an alternative means to reduce risk.

  • Used when primary controls are not feasible.
  • Provides an equivalent level of protection.
  • Must be carefully chosen to match the risk it mitigates.

Memory trick: When the main door is broken, use a strong alternative window.

More Vulnerability Management questions