Which Security Concept Applies to Legacy Host-Based Firewalls?

Security Controls & Risk Management

Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?

  1. Compensating control Source Reference Answer
  2. Network segmentation
  3. Transfer of risk
  4. SNMP traps

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between architectural controls and compensatory measures, with the common trap being misinterpretation of IP filtering as network segmentation.

This question evaluates the application of compensating controls when primary security architectures cannot be deployed on outdated infrastructure. The community consensus confirms that host-based IP restrictions on legacy systems function as substitute safeguards to meet compliance and risk mitigation goals.

Network segmentation is frequently selected because whitelisting internal IPs mimics traffic isolation, but it overlooks the exam's emphasis on legacy constraints that prevent standard perimeter controls, making the host-based rule a compensatory alternative instead.

Community Discussion (11 comments)

shady23 👍 26 Selected: A
A. Compensating control w, the keyword in the question is "legacy". Suppose that you have a legacy Linux server which is not compatible with those network-based firewalls, routers and multi-layer switches which is preventing you not just from building VLANs (Network Segmentation), but also from applying white-listing ACL technique against malicious IP addresses. So, what you're going to do is you are going to use host-based firewalls as a compensation for network appliances to be able to accomplish the similar end-result
Mehsotopes 👍 11 Selected: A
It is not mentioned that internal IP addresses have been separated from other network IP addresses, but that the host-based firewall is only allowed to communicate with, & protect specific internal IP addresses, this would compensate for threats by mitigating possible attack surfaces that those internal addresses might be vulnerable to from OUTSIDE the network.
Chidazz 👍 1 Selected: A
The correct answer is: A. Compensating control Explanation: A compensating control is a security measure implemented to meet security requirements when the primary control is not feasible due to technical or business constraints. In this case, since the system is a legacy Linux system, it might not support modern security features like centralized firewall management. Instead, a host-based firewall is used to restrict access to specific internal IP addresses, serving as an alternative security control. B. Network segmentation refers to dividing a network into separate segments to enhance security and performance, but it is not directly related to a host-based firewall rule. C. Transfer of risk involves shifting risk to another entity, such as purchasing cybersecurity insurance, which is not relevant here. D. SNMP traps are notifications sent from network devices for monitoring and alerting, which also do not apply in this context.
Etc_Shadow28000 👍 4 Selected: A
A. Compensating control A compensating control is a security measure that is put in place to satisfy the requirements of a security policy or standard when the primary control cannot be implemented. In this case, the host-based firewall on a legacy Linux system allowing connections from only specific internal IP addresses serves as a compensating control to protect the system by limiting access to trusted sources. Therefore, the correct answer is: A. Compensating control
dbrowndiver 👍 2 Selected: A
The implementation of a host-based firewall to restrict access is a compensating control because it mitigates the risks associated with potential vulnerabilities in a legacy system by providing an additional layer of protection.
f26ddcd 👍 1 Selected: A
Compensating control
MAKOhunter33333333 👍 3 Selected: A
Whenever there is legacy mentioned it is 99% always going to be compensating controls or compensation.
AutoroTink 👍 3 Selected: B
In the context of the question, which involves a host-based firewall on a legacy Linux system allowing connections from only specific internal IP addresses, the primary goal is to enhance security by limiting access. This is a direct control measure rather than a compensating one. The firewall is not compensating for the inability to implement another control; it is the control itself, enforcing access restrictions based on IP addresses. Configuring the firewall to only allow connections to specific IP addresses, it is segmenting its network.
shady23 👍 1 Selected: A
A. Compensating control
e5c1bb5 👍 1 Selected: B
logical network segmentation includes ACL implementation to allow or dissallow specific IP addresses to communicate with a particular device.
Punjistetics 👍 6
B. Network segmentation. Network segmentation involves dividing a computer network into smaller, isolated networks to improve security and reduce the impact of potential security breaches. By configuring the host-based firewall to allow connections only from specific internal IP addresses, the system is effectively segmenting the network to limit communication to authorized entities, thus enhancing security. Options such as compensating control (A), transfer of risk (C), and SNMP traps (D) do not accurately describe the scenario of restricting connections to specific internal IP addresses through a host-based firewall

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A compensating control is implemented when primary security measures are technically or operationally unfeasible. In this scenario, the legacy Linux system likely lacks compatibility with modern network firewalls, VLANs, or centralized policy enforcement tools. By configuring a host-based firewall to whitelist only specific internal IPs, administrators create an alternative safeguard that fulfills the same security objective: limiting exposure to unauthorized access. This directly aligns with CompTIA’s framework defining compensating controls as substitute mechanisms that satisfy compliance or risk mitigation requirements.

Why the Other Options Are Wrong

Network segmentation involves architecting distinct network zones using switches, routers, or software-defined boundaries, not merely applying IP filters on a single outdated host. Transfer of risk refers to shifting liability through insurance or contracts, which is entirely unrelated to firewall configuration. SNMP traps are event-alerting mechanisms for monitoring, not access control measures. None of these alternatives address the core premise of substituting a missing primary control due to legacy hardware or OS limitations.

Community Comment Notes

Examinees consistently highlight the keyword “legacy” as the decisive clue, noting that older systems often cannot integrate with enterprise-grade perimeter defenses [1][5]. Several users clarify that while IP whitelisting resembles segmentation, the context of inability to deploy standard controls makes it compensatory rather than architectural [2][4]. Commenters also warn against overthinking the technical implementation, emphasizing that Security+ focuses on the management rationale behind control selection [8][10]. This recurring pattern reinforces the importance of recognizing constraint-driven security decisions in performance-based exams.

Official Reference

Exam Strategy

Always scan for constraint keywords like “legacy,” “cannot implement,” or “unavailable” in security questions, as they typically point toward compensating controls rather than standard architectural designs. Focus on the management intent behind the technology rather than the underlying technical configuration itself.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide