How Should You Secure a Legacy Server Running Critical Apps?
Which of the following would be the best way to handle a critical business application that is running on a legacy server?
Community Votes
52% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to select compensating controls when patching isn't possible, with the common trap being confusing segmentation (controlled network separation) with isolation (complete disconnection).
This question evaluates compensating controls for unsupported legacy systems hosting essential business functions. Candidates generally agree that network segmentation offers the optimal balance between mitigating vulnerability exposure and preserving required application connectivity.
Many candidates incorrectly choose Isolation, assuming it completely neutralizes the threat. However, because the scenario specifies a critical application that must remain operational, total isolation would break business continuity, making Segmentation the technically accurate compromise.
Community Discussion (45 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Risk Mitigation Concepts
Legacy servers lack vendor support, meaning they cannot receive security patches or updates. When such a system hosts a critical business application, decommissioning is immediately ruled out due to operational dependencies. Instead, administrators must implement compensating controls to mitigate inherent vulnerabilities without halting business processes.Why Segmentation is the Correct Choice
Segmentation involves dividing the network into smaller, secure zones using VLANs, firewalls, or ACLs. By placing the legacy server in its own segment, you strictly limit inbound and outbound traffic to only the protocols and endpoints absolutely necessary for the application to function. As noted by community experts, this approach significantly reduces the attack surface while maintaining the connectivity required for the application to serve business needs.Why the Other Options Are Incorrect
- Isolation typically implies complete network disconnection or air-gapping. While effective for containing threats, it would render a critical business application unusable, violating availability requirements.
- Hardening focuses on reducing the attack surface through configuration changes and disabling unnecessary services. On legacy systems, hardening options are severely limited by outdated operating systems and software compatibility constraints, making it an insufficient standalone solution.
- Decommissioning eliminates the risk entirely but directly contradicts the premise that the application is critical and must remain in production.
Exam Strategy & Community Consensus
CompTIA frequently tests the nuance between similar-sounding controls. In this case, the exam expects you to recognize that segmentation provides controlled, restricted access rather than absolute cutoff. Community discussions highlight that recognizing keywords like "critical" and "business application" should immediately steer you away from isolation and toward segmentation as the balanced compensating control.Official Reference
Exam Strategy
Always scan for operational constraints like "critical," "must remain online," or "cannot be replaced." When a scenario explicitly prevents remediation (patching/replacing), prioritize compensating controls that maintain availability while restricting access, such as network segmentation or strict firewall rules.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →