Courseiva
mediumMultiple ChoiceObjective-mapped

SSCP Practice Question: A security analyst needs to ensure that a legacy…

A security analyst needs to ensure that a legacy application running on an unsupported operating system remains secure until it can be replaced. Which strategy provides the most effective risk reduction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Move the application to a sandboxed virtual machine and isolate it from the network.

Isolating the legacy application in a sandboxed virtual machine with network restrictions minimizes the attack surface and prevents exploitation of OS-level vulnerabilities. Option B is incorrect because third-party patches are unreliable and may introduce instability or conflicts. Option C is incorrect because upgrading the application is not feasible if it runs on an unsupported OS, and vendor support is unavailable. Option D is incorrect because application whitelisting only controls execution but does not protect against OS vulnerabilities that could compromise the entire system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Move the application to a sandboxed virtual machine and isolate it from the network.

    Why this is correct

    Correct. Sandboxing with network isolation contains the application and limits exposure to threats, reducing risk most effectively.

  • Apply all available security patches from third-party sources.

    Why it's wrong here

    Incorrect. Third-party patches are not reliably supported and may cause conflicts or security gaps.

  • Upgrade the application to the latest version with vendor support.

    Why it's wrong here

    Incorrect. Upgrading the application is not possible if it requires the unsupported OS, so this option does not apply.

  • Implement application whitelisting to allow only approved executables.

    Why it's wrong here

    Incorrect. Application whitelisting only controls executable files but does not protect against OS vulnerabilities or network-based attacks.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.