Courseiva
Security Operations →hardMultiple Choice

ISC2 CC Security Operations Practice Question

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

⚠ Common exam trap

CC often tests compensating controls, and candidates pick monitoring or WAF options because they sound security-focused; the trap is confusing detection (logging) or narrow protection (WAF) with actual risk reduction through containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the system on a separate network segment with strict access controls

Isolating the legacy system on a separate network segment with strict access controls (firewalls, ACLs, micro-segmentation) is a compensating control that reduces the attack surface and limits lateral movement even though the system itself cannot be patched. It directly addresses the risk of exploitation by containing the system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate the system on a separate network segment with strict access controls

    Why this is correct

    Network isolation on a separate segment with strict access controls limits lateral movement and reachability, compensating for the unpatched vulnerabilities that cannot be remediated. This contains exposure without relying on vendor fixes that are no longer available for the end-of-life system.

  • ✗

    Increase logging and monitoring without any network changes

    Why it's wrong here

    Logging and monitoring only detect exploitation after it occurs; they neither block nor constrain access to the unpatched system. It is tempting because visibility is a genuine compensating control, but it is correct when paired with preventive measures or when detection is the stated objective.

  • ✗

    Apply a virtual patch using a web application firewall

    Why it's wrong here

    A web application firewall filters HTTP traffic, so it cannot protect a legacy system whose exploitable service is not web-based. It is tempting because virtual patching genuinely shields unpatched web applications, which is the correct choice when the vulnerable interface is HTTP.

  • ✗

    Remove the system from the network entirely

    Why it's wrong here

    Removing the system entirely eliminates the operational capability the organisation needs, so it is not a compensating control but a denial of service. It is tempting because full isolation genuinely removes network-based exploitation, and would be correct if the system were non-critical or replaceable.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.