nerdexam
CompTIA

CAS-002 · Question #360

The risk manager is reviewing a report which identifies a requirement to keep a business critical legacy system operational for the next two years. The legacy system is out of support because the…

The correct answer is B. Segment the device on its own secure network. A legacy out-of-support embedded system with unknown internals requires compensating controls; network segmentation is the most practical and effective risk reduction measure available.

Enterprise Security

Question

The risk manager is reviewing a report which identifies a requirement to keep a business critical legacy system operational for the next two years. The legacy system is out of support because the vendor and security patches are no longer released. Additionally, this is a proprietary embedded system and little is documented and known about it. Which of the following should the Information Technology department implement to reduce the security risk from a compromise of this system?

Options

  • AVirtualize the system and migrate it to a cloud provider.
  • BSegment the device on its own secure network.
  • CInstall an antivirus and HIDS on the system.
  • DHire developers to reduce vulnerabilities in the code.

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    73% (29)
  • C
    15% (6)
  • D
    8% (3)

Why each option

A legacy out-of-support embedded system with unknown internals requires compensating controls; network segmentation is the most practical and effective risk reduction measure available.

AVirtualize the system and migrate it to a cloud provider.

A proprietary embedded system cannot be virtualized and migrated to a cloud provider because its architecture is hardware-dependent and its internals are undocumented.

BSegment the device on its own secure network.Correct

Segmenting the device on its own isolated network limits the blast radius of any compromise by preventing lateral movement to other systems. Since the system cannot be patched and its code is largely unknown, network isolation acts as a compensating control that contains threats without requiring changes to the system itself. This is a standard recommendation for legacy and end-of-life systems that must remain operational.

CInstall an antivirus and HIDS on the system.

Installing antivirus and HIDS may not be feasible on a proprietary embedded system, and even if possible, these tools cannot patch the underlying unaddressed vulnerabilities.

DHire developers to reduce vulnerabilities in the code.

Hiring developers to reduce vulnerabilities is impractical because the system is proprietary with little documentation, making code analysis and remediation extremely time-consuming and risky within the two-year window.

Concept tested: Network segmentation as compensating control for legacy systems

Source: https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final

Topics

#legacy systems#network segmentation#risk mitigation#end-of-life software

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice