How to Quickly Mitigate Vulnerabilities in Legacy IoT Devices?

A newly identified network access vulnerability has been found in the OS of legacy IoT devices. Which of the following would best mitigate this vulnerability quickly?

  1. Insurance
  2. Patching
  3. Segmentation Source Reference Answer
  4. Replacement

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the prioritization of rapid containment over remediation, with the common trap being the instinct to select patching despite the explicit 'legacy' constraint.

This question evaluates risk mitigation strategies for unsupported assets under time pressure. The community consensus confirms that network segmentation offers the fastest containment when patching is impossible.

Candidates frequently select Patching because it is the standard remediation step for known vulnerabilities, overlooking that legacy IoT devices typically lack vendor support or require extensive testing before updates can be safely deployed.

Community Discussion (12 comments)

KrazyMonkey 👍 21 Selected: C
I've not heard of patching legacy devices... Professor Messer would be disappointed.
CyberSecurity24 👍 11 Selected: C
Patching is a common method for addressing vulnerabilities. However, in the case of legacy devices, patches may no longer be provided, or applying new patches may be difficult. Therefore, it is not suitable as a quick mitigation method, making C. Segmentation the correct answer.
Drey09 👍 1 Selected: C
He's telling mitigate, replace will soulve the problem
ProudFather 👍 1 Selected: D
D. Replacement Since the vulnerability is in the OS of legacy IoT devices, patching might not be feasible due to the age of the devices and the lack of vendor support for updates. In such cases, the most effective mitigation strategy is to replace the vulnerable devices with newer models that have security updates and support. While segmentation and insurance can be helpful, they are not the primary solution to address the vulnerability itself.
dbrowndiver 👍 4 Selected: C
Legacy IoT Devices: These devices often lack the ability to be quickly patched or replaced due to hardware limitations or operational constraints. Segmentation offers a rapid response by limiting access and isolating these devices from critical network resources. Access Control: By segmenting the network, you can apply stricter access controls and monitoring, ensuring that any potential compromise of the IoT devices does not affect the broader network.
SHADTECH123 👍 6 Selected: C
Segmentation would best mitigate the network access vulnerability in the OS of legacy IoT devices quickly. By segmenting the network, you can isolate the vulnerable devices from the rest of the network, thereby limiting potential access and reducing the risk of exploitation. This is often faster than patching or replacing the devices, especially if patches are not immediately available or replacement is not feasible in the short term.
AutoroTink 👍 5 Selected: C
I retract my previous answer. You can't do patching on legacy stuff...MY BAD!
hasquaati 👍 3 Selected: C
Key word is legacy device. Patches may not be available. Segmentation will also be a valid solution for legacy IoT devices. Answer is C.
e5c1bb5 👍 3 Selected: C
theres always trolls/mislead people. legacy devices arent supported anymore. segmentation is the way to go. theres always vulnerabilities in IOT devices. what do you do if you need to use them? SEGMENTATION.
shady23 👍 3 Selected: C
Question #: 729 Topic #: 1 [All SY0-601 Questions] A newly identified network access vulnerability has been found in the OS of legacy IoT devices. Which of the following would best mitigate this vulnerability quickly? A. Insurance B. Patching C. Segmentation D. Replacement Patching doesn't work as it's legacy, Segregation is the quickest option of the remaining three.
AutoroTink 👍 1 Selected: B
Network segmentation could limit the potential impact of the vulnerability but does not address the vulnerability in the devices.
Yoez 👍 1 Selected: B
The option that would best mitigate the vulnerability quickly is patching (option B). Patching involves applying updates or fixes provided by the software vendor to address known vulnerabilities or weaknesses in the system. By promptly patching the OS of the legacy IoT devices, the vulnerability can be mitigated, reducing the risk of exploitation by malicious actors. This is typically the quickest and most direct way to address known vulnerabilities and enhance the security posture of the devices.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Tested

This scenario evaluates your understanding of risk mitigation controls under time constraints, specifically how to handle legacy systems where traditional remediation paths are blocked. The CompTIA Security+ exam frequently emphasizes that mitigation strategies must align with organizational constraints like device age, vendor support status, and urgency.

Why Segmentation is Correct

Network segmentation isolates vulnerable assets from critical infrastructure, significantly reducing the attack surface without requiring immediate software changes. As highlighted by multiple candidates, legacy IoT devices often run outdated operating systems that cannot accept modern security patches due to hardware limitations or discontinued vendor support. By placing these devices in a dedicated VLAN or isolated subnet with strict firewall rules, you achieve rapid containment. This directly addresses the keyword "quickly" while effectively neutralizing the threat of lateral movement.

Why Other Options Fail

  • Patching (B) is the default choice for most vulnerability scenarios, but it fails here because legacy IoT firmware/OSes rarely receive updates, and even if they did, testing and deploying them takes considerable time, violating the "quickly" requirement.
  • Replacement (D) is a long-term remediation strategy, not a quick mitigation. Procuring, configuring, and integrating new devices disrupts operations and requires significant planning.
  • Insurance (A) is a financial risk transfer mechanism, not a technical control. It does nothing to prevent exploitation or limit network access.

Exam Tips & Community Insights

The phrase "legacy devices" is a major red flag in SY0-701 questions. When combined with "quickly," CompTIA expects you to choose an architectural or administrative control over a technical fix. As noted in the community discussions, candidates who initially chose patching were reminded that unsupported equipment simply cannot be patched. Always scan for time-sensitivity and asset constraints to guide your selection toward isolation or compensating controls.

Official Reference

Exam Strategy

Always cross-reference asset lifecycle status with the required action timeline. If a question specifies 'legacy,' 'unsupported,' or 'quickly,' immediately rule out patching and replacement in favor of compensating controls like segmentation, hardening, or network isolation.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide