Which Security Concept Applies to Legacy Host-Based Firewalls?
Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to distinguish between architectural controls and compensatory measures, with the common trap being misinterpretation of IP filtering as network segmentation.
This question evaluates the application of compensating controls when primary security architectures cannot be deployed on outdated infrastructure. The community consensus confirms that host-based IP restrictions on legacy systems function as substitute safeguards to meet compliance and risk mitigation goals.
Network segmentation is frequently selected because whitelisting internal IPs mimics traffic isolation, but it overlooks the exam's emphasis on legacy constraints that prevent standard perimeter controls, making the host-based rule a compensatory alternative instead.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A compensating control is implemented when primary security measures are technically or operationally unfeasible. In this scenario, the legacy Linux system likely lacks compatibility with modern network firewalls, VLANs, or centralized policy enforcement tools. By configuring a host-based firewall to whitelist only specific internal IPs, administrators create an alternative safeguard that fulfills the same security objective: limiting exposure to unauthorized access. This directly aligns with CompTIA’s framework defining compensating controls as substitute mechanisms that satisfy compliance or risk mitigation requirements.Why the Other Options Are Wrong
Network segmentation involves architecting distinct network zones using switches, routers, or software-defined boundaries, not merely applying IP filters on a single outdated host. Transfer of risk refers to shifting liability through insurance or contracts, which is entirely unrelated to firewall configuration. SNMP traps are event-alerting mechanisms for monitoring, not access control measures. None of these alternatives address the core premise of substituting a missing primary control due to legacy hardware or OS limitations.Community Comment Notes
Examinees consistently highlight the keyword “legacy” as the decisive clue, noting that older systems often cannot integrate with enterprise-grade perimeter defenses [1][5]. Several users clarify that while IP whitelisting resembles segmentation, the context of inability to deploy standard controls makes it compensatory rather than architectural [2][4]. Commenters also warn against overthinking the technical implementation, emphasizing that Security+ focuses on the management rationale behind control selection [8][10]. This recurring pattern reinforces the importance of recognizing constraint-driven security decisions in performance-based exams.Official Reference
Exam Strategy
Always scan for constraint keywords like “legacy,” “cannot implement,” or “unavailable” in security questions, as they typically point toward compensating controls rather than standard architectural designs. Focus on the management intent behind the technology rather than the underlying technical configuration itself.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →