Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A company has identified a critical vulnerability in a third-party software component that is integral to its core business application. The vendor has acknowledged the vulnerability but has not yet released a patch, stating it will take several weeks. To reduce immediate risk, the security team implements an Intrusion Prevention System (IPS) rule to block known exploit patterns targeting this specific vulnerability. What type of control is the IPS rule in this scenario?

  1. ADetective control
  2. BPreventive control
  3. CCorrective control
  4. DCompensating control
Show answer & explanation

Correct answer: D. Compensating control

A compensating control is an alternative security measure that is put in place to mitigate the risk associated with a known vulnerability when a primary control (like a patch) is not feasible or available. The IPS rule acts as a temporary measure until a proper patch can be applied.

Why the other options are wrong

  • A. A detective control identifies an attack after it has occurred (e.g., logs, alarms); IPS primarily attempts to block, not just detect.
  • B. A preventive control aims to stop an attack before it happens; while IPS can be preventive, in this context, it's specifically compensating for a missing patch.
  • C. A corrective control fixes issues after they occur (e.g., restoring from backup), which is not the primary function here.

Compensating Control

An alternative security measure that reduces risk when a primary control is not feasible, available, or effective.

  • Used to bridge security gaps temporarily or permanently.
  • Mitigates risk when direct remediation isn't possible.
  • Often implemented when waiting for a patch or update.

Memory trick: Prevent stop, Detect find, Correct fix, Compensate substitute.

More Vulnerability Management questions