Which Security Control Applies to Segmented Legacy Servers?
Which of the following security controls is most likely being used when a critical legacy server is segmented into a private network?
Community Votes
59% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to differentiate between standard preventive controls and compensating controls by recognizing that legacy system constraints necessitate alternative risk-mitigation strategies.
This question evaluates how organizations mitigate vulnerabilities on unpatchable legacy infrastructure. The community consensus identifies network segmentation as a compensating control, serving as an alternative safeguard when primary security measures are technically infeasible.
Candidates frequently choose Preventive because segmentation inherently restricts access, failing to account for the explicit legacy context that makes standard preventive controls like patching impossible, thereby reclassifying the measure as compensating.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Compensating vs. Preventive Controls
In security architecture, a preventive control is designed to stop a threat before it occurs, such as installing patches, updating firmware, or deploying modern firewalls. However, legacy servers often run outdated operating systems or proprietary applications that cannot support current security updates without breaking functionality. When the primary control (patching/upgrading) is infeasible, organizations implement a compensating control—an alternative safeguard that achieves the same security objective.Segmenting the legacy server into a private network directly addresses this constraint. By isolating the vulnerable system from the broader enterprise network, administrators drastically reduce its attack surface and limit lateral movement. As multiple community candidates noted, segmentation acts as a workaround that mitigates risk precisely because standard preventive measures cannot be applied.
Why Other Options Are Incorrect
Preventive controls are generally the first line of defense, but in this scenario, they are explicitly bypassed due to legacy limitations. While segmentation does prevent unauthorized access, the question's emphasis on a "critical legacy server" signals that standard prevention is impossible, making compensation the more accurate classification. Deterrent controls aim to discourage attackers through visible warnings (e.g., warning banners), which segmentation does not provide. Corrective controls restore systems after an incident has occurred (e.g., backups, disaster recovery), which is unrelated to proactive network isolation.Exam Context & Community Insights
The SY0-701 exam frequently pairs "legacy," "unpatchable," or "incompatible" keywords with compensating controls. Candidates who recognized this pattern correctly identified C, while those focusing solely on the mechanical function of segmentation mistakenly selected D. Remember that CompTIA prioritizes risk management logic over pure technical mechanics when legacy constraints are specified.Official Reference
- https://www.nist.gov/publications/security-controls-information-systems-nist-sp-800-53r5
- https://www.cisecurity.org/controls/cis-controls-list
- CompTIA Security+ SY0-701 Official Cert Guide Library, Chapter 2: Security Architecture
- NIST Special Publication 800-39: Managing Information Security Risk
Exam Strategy
When you encounter keywords like "legacy," "cannot be updated," or "primary control unavailable," immediately flag compensating controls as the likely answer. Always ask yourself: "Is this control filling a gap left by an infeasible primary measure?" If yes, it overrides the default preventive classification.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →