An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?
Network isolation on a separate segment with strict access controls limits lateral movement and reachability, compensating for the unpatched vulnerabilities that cannot be remediated. This contains exposure without relying on vendor fixes that are no longer available for the end-of-life system.
Why this answer
Isolating the legacy system on a separate network segment with strict access controls (firewalls, ACLs, micro-segmentation) is a compensating control that reduces the attack surface and limits lateral movement even though the system itself cannot be patched. It directly addresses the risk of exploitation by containing the system.
Exam trap
CC often tests compensating controls, and candidates pick monitoring or WAF options because they sound security-focused; the trap is confusing detection (logging) or narrow protection (WAF) with actual risk reduction through containment.
How to eliminate wrong answers
Option B is wrong because increasing logging and monitoring only improves detection and forensics; it does not reduce the likelihood or impact of exploitation. Option C is wrong because a virtual patch via WAF only protects web application traffic and does not address vulnerabilities in other protocols or services the legacy system may expose. Option D is wrong because removing the system from the network entirely would break the critical operations it supports, which is not acceptable given the scenario.