Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementHard

A security analyst is investigating a persistent vulnerability identified during a recent scan of a legacy application server. The vulnerability is a known remote code execution (RCE) flaw in an outdated library that cannot be patched without breaking critical business functionality. The organization decides not to patch the vulnerability. Which of the following is the MOST appropriate risk mitigation strategy in this scenario?

  1. AImplement a network intrusion prevention system (IPS) to block RCE attempts.
  2. BAccept the risk, as patching is not feasible.
  3. CTransfer the risk by purchasing cyber insurance.
  4. DSchedule the application for immediate decommissioning.
Show answer & explanation

Correct answer: A. Implement a network intrusion prevention system (IPS) to block RCE attempts.

Since patching is not feasible, a compensating control like an IPS can actively monitor and block attempts to exploit the RCE vulnerability, thereby mitigating the risk without requiring a direct patch to the vulnerable component.

Why the other options are wrong

  • B. Accepting the risk without any mitigation for an RCE is generally irresponsible, especially if alternatives exist.
  • C. Cyber insurance transfers financial risk, but does not mitigate the technical risk of the RCE vulnerability itself.
  • D. Immediate decommissioning might be a long-term goal but is often not a feasible immediate mitigation for a critical business application.

Risk Mitigation (Compensating Control)

The process of reducing the likelihood or impact of a risk through the implementation of security controls, especially when direct remediation is not possible.

  • Does not eliminate the vulnerability, but reduces its exploitability or impact.
  • Often involves layered security (defense-in-depth).
  • Requires careful selection and ongoing monitoring.

Memory trick: When you can't patch, 'shield' the weakness with other defenses.

More Vulnerability Management questions