How to Secure Legacy Systems Using Unencrypted Protocols?
A security administrator is addressing an issue with a legacy system that communicates data using an unencrypted protocol to transfer sensitive data to a third party. No software updates that use an encrypted protocol are available, so a compensating control is needed. Which of the following are the most appropriate for the administrator to suggest? (Choose two.)
Community Votes
83% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to apply alternative security architectures when direct protocol upgrades are impossible, with the common trap being the selection of data-at-rest protections like tokenization instead of transport-layer solutions.
This question evaluates the ability to identify compensating controls when legacy systems cannot be upgraded to encrypted protocols. The community consensus confirms that SSH tunneling and network segmentation provide the necessary transport-layer encryption and isolation to protect sensitive data in transit.
Many candidates incorrectly select Tokenization (A), assuming it secures sensitive data across the board. However, tokenization substitutes actual values with non-sensitive tokens for storage or compliance, offering zero protection against cleartext interception during network transmission.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Compensating Controls for Legacy Infrastructure
The scenario presents a constrained environment where direct remediation (patching or replacing the protocol) is explicitly unavailable. In cybersecurity frameworks, administrators must deploy compensating controls—alternative safeguards that mitigate risk without altering the original vulnerable component. The core vulnerability here is data in transit being exposed via an unencrypted legacy protocol.Why SSH Tunneling (C) is Correct
SSH tunneling (secure channel encapsulation) wraps the legacy traffic inside an encrypted SSH session. As highlighted by top-voted community explanations, this allows the unencrypted protocol to traverse a secure channel, effectively neutralizing eavesdropping and man-in-the-middle attacks without requiring modifications to the legacy application.Why Segmentation (D) is Correct
Network segmentation isolates the legacy system into a restricted zone or VLAN. By enforcing strict access control lists (ACLs) and limiting communication paths, segmentation reduces the attack surface. Even if the underlying protocol transmits cleartext, segmentation ensures that only authorized, trusted endpoints can reach the system, minimizing exposure.Why Other Options Are Incorrect
- Tokenization (A) replaces sensitive data with non-sensitive placeholders, primarily used for data at rest or regulatory compliance. It does not encrypt network packets, making it ineffective against transmission vulnerabilities.
- Cryptographic downgrade (B) intentionally weakens encryption algorithms, which directly contradicts security objectives and increases susceptibility to decryption attacks.
- Patch installation (E) is explicitly invalidated by the prompt’s statement that “no software updates... are available.” Selecting this option indicates overlooking explicit scenario constraints.
Community Consensus
Multiple candidates correctly identified CD, emphasizing that tunneling handles encryption while segmentation handles isolation. Some confusion arose regarding tokenization, but the consensus rightly prioritizes transport-layer security for active data transmission.Official Reference
- NIST SP 800-53 Rev. 5 - SC-8 (Transmission Confidentiality and Integrity)
- Cisco Documentation - SSH Port Forwarding and Tunneling Guide
- CompTIA Security+ SY0-701 Official Objectives 1.4 & 3.1
Exam Strategy
When a question explicitly rules out direct fixes like patching or protocol upgrades, immediately pivot to compensating controls such as network isolation, encryption overlays, or strict access policies. Always match the control to the specific data state mentioned in the scenario; use transport-layer solutions (tunnels, VPNs) for data in transit, and masking/tokenization for data at rest.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →