Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

A security auditor is reviewing an organization's endpoint security posture. The auditor discovers that several critical servers are running outdated operating systems and lack current security patches, making them vulnerable to known exploits. However, these servers cannot be immediately upgraded due to application compatibility issues. Which endpoint security design principle should be prioritized to mitigate the risk posed by these vulnerable servers without directly upgrading them?

  1. ARegular Vulnerability Scanning
  2. BEndpoint Hardening
  3. CPatch Management
  4. DNetwork Segmentation and Micro-segmentation
Show answer & explanation

Correct answer: D. Network Segmentation and Micro-segmentation

Network segmentation and micro-segmentation can isolate vulnerable systems, limiting their exposure and preventing potential exploits from spreading to other parts of the network. While not a direct fix for the vulnerability, it's the best immediate mitigation strategy when patching is not an option.

Why the other options are wrong

  • A. Vulnerability scanning identifies the problem but doesn't mitigate the risk; it's a discovery tool.
  • B. Endpoint hardening (e.g., disabling unnecessary services) is important but may not fully protect against OS-level vulnerabilities that cannot be patched.
  • C. Patch management is the ideal solution, but the scenario states immediate upgrades are not possible.

Defense in Depth for Vulnerable Endpoints

Employing multiple layers of security controls to protect endpoints, especially when direct patching or upgrades are not immediately feasible.

  • Assumes that no single security measure is foolproof.
  • Emphasizes compensating controls when primary defenses are weak.
  • Network segmentation is a critical compensating control for unpatchable systems.

Memory trick: If you can't fix the server's 'shield', then put a 'wall' around it.

More Endpoint Security and Secure Network Access questions