Which Security Control Applies to Segmented Legacy Servers?

Which of the following security controls is most likely being used when a critical legacy server is segmented into a private network?

  1. Deterrent
  2. Corrective
  3. Compensating Source Reference Answer
  4. Preventive

Community Votes

C
59%
D
41%

59% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to differentiate between standard preventive controls and compensating controls by recognizing that legacy system constraints necessitate alternative risk-mitigation strategies.

This question evaluates how organizations mitigate vulnerabilities on unpatchable legacy infrastructure. The community consensus identifies network segmentation as a compensating control, serving as an alternative safeguard when primary security measures are technically infeasible.

Candidates frequently choose Preventive because segmentation inherently restricts access, failing to account for the explicit legacy context that makes standard preventive controls like patching impossible, thereby reclassifying the measure as compensating.

Community Discussion (18 comments)

RoRoRoYourBoat 👍 8 Selected: C
C, compensating.
EngAbood 👍 2 Selected: D
Chatgpt said D. Preventive : ( , and when ever i see legacy i chose compensating :(
fc040c7 👍 3 Selected: C
there have been multiple questions with legacy items being compensated for with segmentation. this is no different. I am going with C.
esko636 👍 1 Selected: C
Compensating controls provide alternative measures to mitigate risk when the primary control is not feasible. If the legacy server cannot be patched or upgraded, segmenting it into a private network acts as a compensating control by restricting access and reducing the risk posed by its vulnerabilities.
d06e2b4 👍 4 Selected: C
Segmentation of a critical legacy server into a private network is a compensating control because it addresses security risks when the legacy system cannot be updated or secured using standard measures, like patches or modern preventive controls.
5787808 👍 2 Selected: D
D. Preventive
viktorrdlyi 👍 3 Selected: D
Preventive because we aint compensating anything!! Nothing mentioned In the question to compensate!
fmeox567 👍 1 Selected: D
D. Preventive Preventive controls are designed to stop or mitigate unwanted actions or events before they happen. By segmenting a critical legacy server into a private network, the organization is aiming to prevent unauthorized access and potential threats, thus isolating the server from the broader network and reducing the risk of compromise.
famuza77 👍 1
C, Compensating
BluezClues 👍 1 Selected: C
The correct answer is C. Compensating. When a critical legacy server is segmented into a private network, the security control being used is likely compensating. This is because the legacy server may not support modern security features, and network segmentation is implemented as a workaround to mitigate risks and protect it from external threats. A compensating control is used to achieve a level of security equivalent to the one required when it is not possible to implement the primary control. The other options: - A. Deterrent is designed to discourage malicious actions, such as warning signs or legal warnings. - B. Corrective is aimed at fixing issues after an incident has occurred. - D. Preventive is used to stop attacks from happening in the first place, but in this case, segmentation is compensating for the server's inherent vulnerabilities. Thus, network segmentation is a "compensating" control.
goku5786 👍 1 Selected: D
D. Preventive
nillie 👍 1 Selected: C
The most likely security control being used when a critical legacy server is segmented into a private network is: C. Compensating A compensating control is implemented when the primary control (such as patching or updating a legacy server) is not feasible. Segmenting the legacy server into a private network is a compensating control because it mitigates risk by limiting the server's exposure without requiring changes to the server itself, which might not be possible due to its legacy status.
a0bfa81 👍 1 Selected: D
Segmenting a critical legacy server into a private network is a preventive security control. It helps to protect the server from unauthorized access and potential attacks by isolating it from the rest of the network, thereby reducing the risk of security breaches. Preventive controls are designed to stop security incidents before they occur.
jsmthy 👍 1 Selected: C
compensating, because the best preventative action is to remove the server altogether. You are mitigating the risk by segmenting a vulnerable legacy server.
chasingsummer 👍 1 Selected: D
D. Preventive
koala_lay 👍 1 Selected: D
Agree to D. Preventive Segmenting a critical legacy server into a private network is a preventive measure designed to reduce the risk of unauthorized access and protect sensitive data by controlling traffic to and from the server.
Glacier88 👍 1 Selected: D
Preventive controls: These controls are designed to prevent security incidents from occurring in the first place. By segmenting the critical legacy server into a private network, the organization is taking steps to prevent unauthorized access or attacks on that system. Compensating controls: Compensating controls are used to mitigate the risks associated with other security controls that are not in place or are ineffective. While segmentation could be considered a compensating control in some cases, it's primarily a preventive control in this scenario.
BugG5 👍 1
D - preventive. Segmentation of a critical legacy server into a private network is primarily aimed at preventing unauthorized access and ensuring the server’s security. This control falls under the category of Preventive Controls, as its primary goal is to prevent an incident from occurring. Preventive controls, attempt to prevent an incident from occurring by restricting access, implementing barriers, or enforcing policies. In this case, segmenting the critical legacy server into a private network serves as a preventive measure to restrict access and prevent potential security breaches.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Compensating vs. Preventive Controls

In security architecture, a preventive control is designed to stop a threat before it occurs, such as installing patches, updating firmware, or deploying modern firewalls. However, legacy servers often run outdated operating systems or proprietary applications that cannot support current security updates without breaking functionality. When the primary control (patching/upgrading) is infeasible, organizations implement a compensating control—an alternative safeguard that achieves the same security objective.

Segmenting the legacy server into a private network directly addresses this constraint. By isolating the vulnerable system from the broader enterprise network, administrators drastically reduce its attack surface and limit lateral movement. As multiple community candidates noted, segmentation acts as a workaround that mitigates risk precisely because standard preventive measures cannot be applied.

Why Other Options Are Incorrect

Preventive controls are generally the first line of defense, but in this scenario, they are explicitly bypassed due to legacy limitations. While segmentation does prevent unauthorized access, the question's emphasis on a "critical legacy server" signals that standard prevention is impossible, making compensation the more accurate classification. Deterrent controls aim to discourage attackers through visible warnings (e.g., warning banners), which segmentation does not provide. Corrective controls restore systems after an incident has occurred (e.g., backups, disaster recovery), which is unrelated to proactive network isolation.

Exam Context & Community Insights

The SY0-701 exam frequently pairs "legacy," "unpatchable," or "incompatible" keywords with compensating controls. Candidates who recognized this pattern correctly identified C, while those focusing solely on the mechanical function of segmentation mistakenly selected D. Remember that CompTIA prioritizes risk management logic over pure technical mechanics when legacy constraints are specified.

Official Reference

Exam Strategy

When you encounter keywords like "legacy," "cannot be updated," or "primary control unavailable," immediately flag compensating controls as the likely answer. Always ask yourself: "Is this control filling a gap left by an infeasible primary measure?" If yes, it overrides the default preventive classification.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide