Mitigating Risk for Unpatchable Legacy SCADA Controllers
A municipality implements an IoT device discovery scanner and finds a legacy controller for a critical internal utility SCADA service that is running firmware with multiple vulnerabilities. Unfortunately, the controller cannot be upgraded, and a replacement for it is not available for at least a year. Which of the following is the best action to take to mitigate the risk posed by this controller in the meantime?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the hierarchy of risk controls, specifically highlighting that logical isolation (A) is preferred over simple quarantine (C) or internet blocking (D) when physical air-gapping isn't feasible.
This question addresses the best mitigation strategy for a legacy SCADA device with known vulnerabilities that cannot be patched or replaced. It establishes that network isolation is superior to quarantine or firewall-only rules for critical OT environments.
Many candidates choose Option C (Quarantine in a VLAN), confusing standard IT patching procedures with Operational Technology (OT) security requirements where strict connectivity constraints are necessary.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because 'isolating' and 'constraining connectivity' directly addresses the lack of patchability by reducing the attack surface. In SCADA/OT environments, you must limit lateral movement while maintaining necessary operational communication. This approach effectively neutralizes the vulnerability without disrupting the critical utility service.Why the Other Options Are Wrong
Option B is incorrect because removing the controller would halt the critical utility service, which is not an acceptable trade-off given the one-year timeline for replacement. Option C is insufficient because a VLAN used for patching implies broader network access and potential exposure to other threats; it does not constrain connectivity as strictly as isolation. Option D only blocks internet traffic but leaves the controller vulnerable to internal lateral movement attacks from compromised hosts within the municipal network.Community Comment Notes
Community consensus strongly favors Option A, with users noting that 'Isolate = Air gap' in this context. One user noted they initially considered C but realized it was incorrect because there is no reason to put it in a patching VLAN. Another emphasized that isolating minimizes the impact on overall network security.Exam Strategy
When dealing with legacy devices that cannot be patched, look for options that minimize the attack surface through isolation rather than just filtering specific ports. Remember that 'quarantine' often implies a temporary holding area with some network access, whereas 'isolation' implies strict separation.
Frequently Asked Questions
Why is quarantining in a VLAN (C) wrong for SCADA?
VLANs provide logical separation but still allow network communication. For unpatchable critical assets, stricter isolation is needed to prevent lateral movement.
Can I just block internet access (D)?
No. Blocking internet doesn't stop internal attackers or malware from spreading laterally to the controller from other compromised devices on the same network.