How to Quickly Mitigate Vulnerabilities in Legacy IoT Devices?
A newly identified network access vulnerability has been found in the OS of legacy IoT devices. Which of the following would best mitigate this vulnerability quickly?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the prioritization of rapid containment over remediation, with the common trap being the instinct to select patching despite the explicit 'legacy' constraint.
This question evaluates risk mitigation strategies for unsupported assets under time pressure. The community consensus confirms that network segmentation offers the fastest containment when patching is impossible.
Candidates frequently select Patching because it is the standard remediation step for known vulnerabilities, overlooking that legacy IoT devices typically lack vendor support or require extensive testing before updates can be safely deployed.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Tested
This scenario evaluates your understanding of risk mitigation controls under time constraints, specifically how to handle legacy systems where traditional remediation paths are blocked. The CompTIA Security+ exam frequently emphasizes that mitigation strategies must align with organizational constraints like device age, vendor support status, and urgency.Why Segmentation is Correct
Network segmentation isolates vulnerable assets from critical infrastructure, significantly reducing the attack surface without requiring immediate software changes. As highlighted by multiple candidates, legacy IoT devices often run outdated operating systems that cannot accept modern security patches due to hardware limitations or discontinued vendor support. By placing these devices in a dedicated VLAN or isolated subnet with strict firewall rules, you achieve rapid containment. This directly addresses the keyword "quickly" while effectively neutralizing the threat of lateral movement.Why Other Options Fail
- Patching (B) is the default choice for most vulnerability scenarios, but it fails here because legacy IoT firmware/OSes rarely receive updates, and even if they did, testing and deploying them takes considerable time, violating the "quickly" requirement.
- Replacement (D) is a long-term remediation strategy, not a quick mitigation. Procuring, configuring, and integrating new devices disrupts operations and requires significant planning.
- Insurance (A) is a financial risk transfer mechanism, not a technical control. It does nothing to prevent exploitation or limit network access.
Exam Tips & Community Insights
The phrase "legacy devices" is a major red flag in SY0-701 questions. When combined with "quickly," CompTIA expects you to choose an architectural or administrative control over a technical fix. As noted in the community discussions, candidates who initially chose patching were reminded that unsupported equipment simply cannot be patched. Always scan for time-sensitivity and asset constraints to guide your selection toward isolation or compensating controls.Official Reference
Exam Strategy
Always cross-reference asset lifecycle status with the required action timeline. If a question specifies 'legacy,' 'unsupported,' or 'quickly,' immediately rule out patching and replacement in favor of compensating controls like segmentation, hardening, or network isolation.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →