nerdexam
CompTIA

CAS-003 · Question #564

A regional transportation and logistics company recently hired its first Chief Information Security Officer (CISO). The CISO's first project after onboarding involved performing a vulnerability…

The correct answer is C. The company should implement a WAF in front of the vulnerable application to filter out any. A WAF (Web Application Firewall) is a compensating control that can filter and block malicious requests targeting known vulnerabilities in the legacy application without requiring any changes to the application itself. This directly addresses the business constraint - the app…

Risk Management

Question

A regional transportation and logistics company recently hired its first Chief Information Security Officer (CISO). The CISO's first project after onboarding involved performing a vulnerability assessment against the company's public facing network. The completed scan found a legacy collaboration platform application with a critically rated vulnerability. While discussing this issue with the line of business, the CISO learns the vulnerable application cannot be updated without the company incurring significant losses due to downtime or new software purchases. Which of the following BEST addresses these concerns?

Options

  • AThe company should plan future maintenance windows such legacy application can be
  • BThe CISO must accept the risk of the legacy application, as the cost of replacing the
  • CThe company should implement a WAF in front of the vulnerable application to filter out any
  • DThe company should build a parallel system and perform a cutover from the old application to

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (25)
  • D
    3% (1)

Explanation

A WAF (Web Application Firewall) is a compensating control that can filter and block malicious requests targeting known vulnerabilities in the legacy application without requiring any changes to the application itself. This directly addresses the business constraint - the app cannot be patched or replaced without incurring prohibitive costs. Option A (scheduling a maintenance window) still requires updating the software, which the business said it cannot do. Option B (accepting the risk) is poor practice when a viable control exists. Option D (parallel system cutover) carries the same prohibitive cost concerns as purchasing new software, making it impractical.

Topics

#legacy systems#WAF#vulnerability management#compensating controls

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice