Mitigating Risk for Unpatchable Legacy SCADA Controllers

Answer Correct answer: A — Isolate the controller from the rest of the network and constrain connectivity.

A municipality implements an IoT device discovery scanner and finds a legacy controller for a critical internal utility SCADA service that is running firmware with multiple vulnerabilities. Unfortunately, the controller cannot be upgraded, and a replacement for it is not available for at least a year. Which of the following is the best action to take to mitigate the risk posed by this controller in the meantime?

  1. Isolate the controller from the rest of the network and constrain connectivity. Correct Answer
  2. Remove the controller from the network altogether.
  3. Quarantine the controller in a VLAN used for device patching from the internet.
  4. Configure the internet firewall to deny any internet access to or from the controller.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the hierarchy of risk controls, specifically highlighting that logical isolation (A) is preferred over simple quarantine (C) or internet blocking (D) when physical air-gapping isn't feasible.

This question addresses the best mitigation strategy for a legacy SCADA device with known vulnerabilities that cannot be patched or replaced. It establishes that network isolation is superior to quarantine or firewall-only rules for critical OT environments.

Many candidates choose Option C (Quarantine in a VLAN), confusing standard IT patching procedures with Operational Technology (OT) security requirements where strict connectivity constraints are necessary.

Community Discussion (7 comments)

Gigi42 👍 2 Selected: A
This question is similar to Q #815, where there was a legacy device with no support that had many vulnerabilities. Everyone chose Screened subnet and very few chose air gap. In this scenario, it pretty much says the same thing: legacy device with vulnerabilities, and now everyone is saying isolate. Isolate = Air gap
shady23 👍 1 Selected: A
Isolate the controller from the rest of the network and constrain connectivity.
russian 👍 2 Selected: A
I first thought its C but its definitely A, no reason to quarantine it in a VLAN.
salah112 👍 3 Selected: A
A. Isolate the controller from the rest of the network and constrain connectivity. Given that the legacy controller cannot be upgraded, and a replacement is not available for at least a year, the best action to mitigate the risk posed by this controller is to isolate it from the rest of the network and constrain its connectivity. This approach minimizes the potential attack surface and limits the impact of vulnerabilities in the controller.
ganymede 👍 1
A. Isolate the controller from the rest of the network and constrain connectivity.
johnabayot 👍 1 Selected: A
A. This is an effective way to protect the legacy controller and the SCADA system until a replacement is available.
Hs1208 👍 1 Selected: A
A. Isolate the controller from the rest of the network and constrain connectivity. This helps minimize the potential impact of the vulnerabilities on the overall network security.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because 'isolating' and 'constraining connectivity' directly addresses the lack of patchability by reducing the attack surface. In SCADA/OT environments, you must limit lateral movement while maintaining necessary operational communication. This approach effectively neutralizes the vulnerability without disrupting the critical utility service.

Why the Other Options Are Wrong

Option B is incorrect because removing the controller would halt the critical utility service, which is not an acceptable trade-off given the one-year timeline for replacement. Option C is insufficient because a VLAN used for patching implies broader network access and potential exposure to other threats; it does not constrain connectivity as strictly as isolation. Option D only blocks internet traffic but leaves the controller vulnerable to internal lateral movement attacks from compromised hosts within the municipal network.

Community Comment Notes

Community consensus strongly favors Option A, with users noting that 'Isolate = Air gap' in this context. One user noted they initially considered C but realized it was incorrect because there is no reason to put it in a patching VLAN. Another emphasized that isolating minimizes the impact on overall network security.

Exam Strategy

When dealing with legacy devices that cannot be patched, look for options that minimize the attack surface through isolation rather than just filtering specific ports. Remember that 'quarantine' often implies a temporary holding area with some network access, whereas 'isolation' implies strict separation.

Frequently Asked Questions

Why is quarantining in a VLAN (C) wrong for SCADA?

VLANs provide logical separation but still allow network communication. For unpatchable critical assets, stricter isolation is needed to prevent lateral movement.

Can I just block internet access (D)?

No. Blocking internet doesn't stop internal attackers or malware from spreading laterally to the controller from other compromised devices on the same network.

Related Analysis

← Back to SY0-601 Study Guide