How Should You Secure a Legacy Server Running Critical Apps?

Which of the following would be the best way to handle a critical business application that is running on a legacy server?

  1. Segmentation Source Reference Answer
  2. Isolation
  3. Hardening
  4. Decommissioning

Community Votes

A
52%
B
48%

52% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to select compensating controls when patching isn't possible, with the common trap being confusing segmentation (controlled network separation) with isolation (complete disconnection).

This question evaluates compensating controls for unsupported legacy systems hosting essential business functions. Candidates generally agree that network segmentation offers the optimal balance between mitigating vulnerability exposure and preserving required application connectivity.

Many candidates incorrectly choose Isolation, assuming it completely neutralizes the threat. However, because the scenario specifies a critical application that must remain operational, total isolation would break business continuity, making Segmentation the technically accurate compromise.

Community Discussion (45 comments)

Etc_Shadow28000 👍 20 Selected: A
A. Segmentation Segmentation is the best approach to handle a critical business application running on a legacy server. By segmenting the legacy server from the rest of the network, you can limit the potential impact of any vulnerabilities associated with the legacy system. This approach allows the critical application to continue running while minimizing the risk to the rest of the network. Therefore, the correct answer is: A. Segmentation
AutoroTink 👍 9 Selected: C
Hardening involves implementing security measures to protect the application from threats while maintaining its availability. Segmentation and isolation can also be part of a security strategy, they are more about limiting access or separating the legacy system from other network segments, which might not be feasible for a critical business application that requires interaction with other systems.
JoeRealCool 👍 1 Selected: A
In this situation, I don't think hardening makes sense. Because it is a legacy system, it will still be vulnerable regardless of the security configuration of the system. If you add a firewall before the server, that starts to become segmentation. I also think that there is a theme here with the question bank for these types of questions where the answer for dealing with legacy servers is either segmentation or compensating controls. Decommissioning would be the best way but I don't think it works for this particular question because it doesn't recommend what to do after decommissioning so that the critical application can still run. Isolation doesn't make sense because then the network can't access the critical application. I hate these types of questions.
Konversation 👍 1 Selected: B
B. Isolation CompTIA Sec+ Student Guide - Unsupported systems and Applications: "One strategy for dealing with unsupported apps that cannot be replaced is to try to isolate them from other systems. The idea is to reduce opportunities for a threat actor to access the vulnerable app and run exploit code. Using isolation as a substitute for patch management is an example of a compensating control."
93d818a 👍 1 Selected: B
In the context of the CompTIA Security+ (SY0-701) Exam Objectives, managing legacy systems is crucial due to their inherent security challenges. These systems often lack vendor support, making them susceptible to vulnerabilities. To mitigate risks associated with legacy systems, isolation is a recommended strategy. Isolating legacy systems involves restricting their network access to essential communications only, thereby reducing potential attack vectors
test_arrow 👍 1 Selected: B
B. Isolation Explanation: A legacy server running a critical business application poses security risks because it may no longer receive updates or security patches. Isolation is the best approach because it minimizes the risk of compromise while allowing the application to continue running.
585402e 👍 3 Selected: A
For this question i choose "Segmentation" but.. Segmentation is ideal when the legacy server requires internet access through the company's web proxy. It keeps the server within a secure, isolated network segment, ensuring it can access the internet while minimizing risks to other parts of the network. Isolation is the better approach when the legacy server only needs to be powered on for specific local operations. It provides a higher level of security by completely separating the server from other systems and network resources.
Anyio 👍 1 Selected: A
A. Segmentation. Segmentation isolates the legacy server within the network, minimizing the attack surface while still allowing necessary communication. Other options: B-Isolation may be too restrictive C-Hardening is limited due to outdated systems D-Decommissioning isn't viable for critical applications. Segmentation provides a balanced approach, enhancing security while maintaining functionality.
ITExperts 👍 1 Selected: C
A legacy server is a server that is running outdated or unsupported software or hardware, which may pose security risks and compatibility issues Hardening is the process of applying security measures and configurations to a system to reduce its attack surface and vulnerability
41c27e6 👍 1 Selected: C
How about patching the legacy server first?
Phatcharaphon 👍 3 Selected: B
Isolation is the most effective approach to ensure the legacy system is protected while continuing to support critical business functions, making B the correct choice.
laternak26 👍 2 Selected: B
Given the constraints associated with legacy systems, B. Isolation is the most practical approach to mitigate security risks. By isolating the legacy server, you can protect it and the broader network from potential vulnerabilities.
ProudFather 👍 1 Selected: D
D. Decommissioning While segmentation, isolation, and hardening can be useful security measures, the best long-term solution for a legacy application is to decommission it and replace it with a more modern and secure alternative. Legacy systems are often difficult to patch, update, and secure, making them prime targets for cyberattacks. By decommissioning the legacy server, the organization can reduce its attack surface and improve its overall security posture.
dC_Furious 👍 1
A Segmentation This is a critical business application if the system is isolated it would not function properly segmentation would Allow the legacy server to continue operating within the network while restricting its communication to only necessary systems and users. This reduces the attack surface and helps protect the rest of the network from potential vulnerabilities associated with the legacy server.
3dk1 👍 2 Selected: A
It is not Isolation. Isolation would mean blocking access altogether... That means it is either A or C. I am going with A though.
chalaka 👍 1 Selected: B
B. Isolation : Isolation goes a step further and completely cuts a system (critical business application) off from access to or from outside networks.
839cf0e 👍 1 Selected: C
One of the best ways to handle a legacy server running a critical business application is to harden it. Hardening is the process of applying security measures and configurations to a system to reduce its attack surface and vulnerability
9ef4a35 👍 1
B. Isolation
Veerus97 👍 1 Selected: B
A. Segmentation
Murtuza 👍 1 Selected: A
A. Segmentation
georgepg 👍 1 Selected: B
Isolation
famuza77 👍 1 Selected: B
"critical business application", Isolation its the correct answer
ok_im_here 👍 2 Selected: B
After reading the Comptia book and asking several AI tools, B seems to be the right answer.
c7b3ff0 👍 2 Selected: B
My study guide says isolation is the answer and its really seems like it could also situationally be A. I hate how some of these questions are constructed. I guess I'd go B on the test.
User92 👍 1 Selected: A
The keyword here is "critical business application", "B" is the best choice for maximum security. However, a "critical business application" needs to balance security with resource efficiency (compensating mechanism), so I would go with "A".
Laura5859 👍 5 Selected: B
The Official CompTIA Security+ Study Guide (Exam SY0-701) pg 32 has an explanation mark that says: "One strategy for dealing with unsupported apps that cannot be replaced is to try to isolate them from other systems. The idea is to reduce opportunities for a threat actor to access the vulnerable app and run exploit code. Using isolation as a substitute for patch management is an example of a compensating control."
Laura5859 👍 2
The Official CompTIA Security+ Study Guide (Exam SY0-701) has an explanation mark that says: "One strategy for dealing with unsupported apps that cannot be replaced is to try to isolate them from other systems. The idea is to reduce opportunities for a threat actor to access the vulnerable app and run exploit code. Using isolation as a substitute for patch management is an example of a compensating control."
Ty13 👍 2 Selected: B
B. Isolation Segmenting a network means breaking the network into smaller subnets, like one for HR, one for Payroll, one for Management, etc. The idea being that you can end connections to one segment entirely in the event of a compromise, without impacting other segments. Isolation is just the next step further - if a device is old and unsupported, like Windows XP, then you'd want to have it completely on its own where it can't touch the rest of the network inappropriately.
koala_lay 👍 1 Selected: A
Agree to answer: A. segmentation
baronvon 👍 3 Selected: B
B. Isolation The reason for this comes from the CompTIA Security+ study guide: "In cases where the organization simply must continue using an unsupported operating system, best practice dictates isolating the system as much as possible, preferably not connecting it to any network, and applying as many compensating security controls as possible, such as increased monitoring and implementing strict network firewall rules."
a4e15bd 👍 3
Isolation is used to completely separate a system from the network which is ideal if the primary goal is to eliminate any potential risk of legacy server compromising other systems. It is more extreme measure, typically applied when the application doesnt need to communicate with other systems or when the risk is deemed too high. Segmentation on the other hand is used to limit the legacy applications communication to only necessary interactions which still protects the rest of the network but allows the application to function normally. It is more nuanced approach allowing for controlled interactions while still reducing risk. So A. Segmentation is the best option because it provides a balance between security and functionality allow the legacy system to continue operating within a restricted and monitored environment.
nesquick0 👍 1 Selected: C
C. Hardening
dbrowndiver 👍 1 Selected: B
Not Fully Isolated: While segmentation improves security, it doesn't offer the complete separation provided by isolation. If the legacy server is compromised, segmentation might not prevent the spread of threats as effectively as isolation. Complex Implementation: Requires careful planning to ensure correct segmentation, which can introduce complexity without providing the full benefits of isolation.
dbrowndiver 👍 3 Selected: B
Isolation is the best approach for handling a critical business application on a legacy server. It involves separating the legacy system from the rest of the network, thereby reducing the risk of security breaches affecting the broader network while still allowing the application to function as needed. Isolation: This approach involves creating a separate environment for the legacy system, preventing it from directly interacting with other network components. Isolation minimizes exposure to threats and limits the potential impact of vulnerabilities. In this Scenario Application:Security Risk Mitigation: By isolating the legacy server, the company can protect its network from potential vulnerabilities that the outdated system might introduce. This is crucial for critical applications that cannot be immediately upgraded or replaced. Isolation allows the application to continue running without immediate disruption, maintaining business continuity while planning for future upgrades or replacements. Why this is best over the other choices: Isolation balances the need to keep the application operational while protecting the rest of the network from potential risks associated with legacy systems.
NoobusAurelius 👍 1
Answer is A. Segmentation, if you read the question it says critical Business application, isolating the server would impact it's ability to interact with other systems on the Network and therefore Business Operations will be affected. Hardening has the potential to affect server performance and being a legacy server it may not be compatible with current software, hardware or other hardening techniques. Decommisioning could be an option if the application can be migrated out of hours to a brand new server, but that isn't really what the question is alluding to.
WOW_ThatsCrazy 👍 1 Selected: B
Isolation is the process of separating the legacy system from the rest of the network to reduce the risk of vulnerabilities being exploited. This approach allows the legacy application to continue operating while minimizing its exposure to potential threats. Segmentation is similar but generally applies to creating separate network segments for security. However, isolation goes further by limiting interactions strictly to what is necessary.
cdsu 👍 1
B. Isolation ...managing a critical business application on a legacy server. By separating the legacy server from the rest of the network to prevent potential threats from spreading. This way effective in protecting the critical application from vulnerabilities inherent to the legacy system.
Dean1065 👍 1 Selected: A
A. Segmentation is one of the only things you can do for legacy systems.
Shaman73 👍 3
• B. Isolation Segmentation, wenn die Application mehrere Systeme bräuchte; Härtung geht nicht mehr; Decommissioning noch nicht….
MAKOhunter33333333 👍 5 Selected: A
Isolation is like completely separate, while segmentation means it is still on the network providing service
SHADTECH123 👍 2 Selected: B
Isolation involves separating the legacy server from other parts of the network to minimize potential security risks while maintaining its operational role. This can help protect the rest of the network from vulnerabilities associated with the legacy system, ensuring that the critical application remains secure and functional.
9547adc 👍 1
Isolation because Segmentation involves dividing a network into separate segments or zones to control the flow of traffic and limit the scope of potential security breaches. It's typically applied at the network level to create boundaries between different parts of a network, such as separating internal networks from external ones or segmenting departments within an organization. Isolation, on the other hand, focuses on physically or logically separating a specific system, application, or resource from the rest of the network or environment. It involves placing the critical business application on its own server or within its own isolated environment to reduce the risk of unauthorized access or compromise.
e5c1bb5 👍 2 Selected: A
segmentation because the device is STILL running a critical application. therefore it needs to be connected to the network. a compensating mechanism for this scenario would be segmentation as this would limit the ability of an attacker to pivot from the vulnerable server to the rest of the network.
shady23 👍 1 Selected: A
A. Segmentation
Punjistetics 👍 2 Selected: B
B. Isolation Isolation would be the best approach for handling a critical business application running on a legacy server. By isolating the legacy server, you minimize its exposure to potential security threats and reduce the risk of compromising other parts of the network. This allows you to maintain the functionality of the critical application while also enhancing security.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Risk Mitigation Concepts

Legacy servers lack vendor support, meaning they cannot receive security patches or updates. When such a system hosts a critical business application, decommissioning is immediately ruled out due to operational dependencies. Instead, administrators must implement compensating controls to mitigate inherent vulnerabilities without halting business processes.

Why Segmentation is the Correct Choice

Segmentation involves dividing the network into smaller, secure zones using VLANs, firewalls, or ACLs. By placing the legacy server in its own segment, you strictly limit inbound and outbound traffic to only the protocols and endpoints absolutely necessary for the application to function. As noted by community experts, this approach significantly reduces the attack surface while maintaining the connectivity required for the application to serve business needs.

Why the Other Options Are Incorrect

  • Isolation typically implies complete network disconnection or air-gapping. While effective for containing threats, it would render a critical business application unusable, violating availability requirements.
  • Hardening focuses on reducing the attack surface through configuration changes and disabling unnecessary services. On legacy systems, hardening options are severely limited by outdated operating systems and software compatibility constraints, making it an insufficient standalone solution.
  • Decommissioning eliminates the risk entirely but directly contradicts the premise that the application is critical and must remain in production.

Exam Strategy & Community Consensus

CompTIA frequently tests the nuance between similar-sounding controls. In this case, the exam expects you to recognize that segmentation provides controlled, restricted access rather than absolute cutoff. Community discussions highlight that recognizing keywords like "critical" and "business application" should immediately steer you away from isolation and toward segmentation as the balanced compensating control.

Official Reference

Exam Strategy

Always scan for operational constraints like "critical," "must remain online," or "cannot be replaced." When a scenario explicitly prevents remediation (patching/replacing), prioritize compensating controls that maintain availability while restricting access, such as network segmentation or strict firewall rules.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide