How to Secure Legacy Systems Using Unencrypted Protocols?

A security administrator is addressing an issue with a legacy system that communicates data using an unencrypted protocol to transfer sensitive data to a third party. No software updates that use an encrypted protocol are available, so a compensating control is needed. Which of the following are the most appropriate for the administrator to suggest? (Choose two.)

  1. Tokenization
  2. Cryptographic downgrade
  3. SSH tunneling Source Reference Answer
  4. Segmentation Source Reference Answer
  5. Patch installation

Community Votes

CD
83%
AD
17%

83% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to apply alternative security architectures when direct protocol upgrades are impossible, with the common trap being the selection of data-at-rest protections like tokenization instead of transport-layer solutions.

This question evaluates the ability to identify compensating controls when legacy systems cannot be upgraded to encrypted protocols. The community consensus confirms that SSH tunneling and network segmentation provide the necessary transport-layer encryption and isolation to protect sensitive data in transit.

Many candidates incorrectly select Tokenization (A), assuming it secures sensitive data across the board. However, tokenization substitutes actual values with non-sensitive tokens for storage or compliance, offering zero protection against cleartext interception during network transmission.

Community Discussion (5 comments)

jennyka76 👍 2 Selected: CD
Explanation: C. SSH tunneling: SSH tunneling can securely encrypt and encapsulate unencrypted traffic sent from the legacy system. It allows the unencrypted protocol to communicate over a secure channel, ensuring sensitive data is protected in transit. This compensating control effectively mitigates the risk of sending data in cleartext. D. Segmentation: Network segmentation isolates the legacy system within a secure zone, limiting its exposure to other parts of the network. By restricting communication pathways, segmentation reduces the attack surface and protects sensitive data from unauthorized access.
Aces155 👍 1 Selected: AD
I think A and D. A replaces the sensitive data with non-sensitive substitutes and D encrypts communication over an insecure network
beebax 👍 2
i don't get why CD is the answer since in the question it isn't stated that they are concerned about the impact of the breach and want to contain it they are just addressing the unencrypted protocols issue?
Phatcharaphon 👍 1 Selected: CD
C. SSH tunneling: This encrypts the communication between systems, ensuring the sensitive data is securely transferred. D. Segmentation: This can be used to isolate the legacy system, reducing the risk of exposing sensitive data, though it doesn’t directly encrypt the communication.
Exam_Prep221 👍 2 Selected: CD
Explanation: C. SSH tunneling: SSH tunneling can securely encrypt and encapsulate unencrypted traffic sent from the legacy system. It allows the unencrypted protocol to communicate over a secure channel, ensuring sensitive data is protected in transit. This compensating control effectively mitigates the risk of sending data in cleartext. D. Segmentation: Network segmentation isolates the legacy system within a secure zone, limiting its exposure to other parts of the network. By restricting communication pathways, segmentation reduces the attack surface and protects sensitive data from unauthorized access.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Compensating Controls for Legacy Infrastructure

The scenario presents a constrained environment where direct remediation (patching or replacing the protocol) is explicitly unavailable. In cybersecurity frameworks, administrators must deploy compensating controls—alternative safeguards that mitigate risk without altering the original vulnerable component. The core vulnerability here is data in transit being exposed via an unencrypted legacy protocol.

Why SSH Tunneling (C) is Correct

SSH tunneling (secure channel encapsulation) wraps the legacy traffic inside an encrypted SSH session. As highlighted by top-voted community explanations, this allows the unencrypted protocol to traverse a secure channel, effectively neutralizing eavesdropping and man-in-the-middle attacks without requiring modifications to the legacy application.

Why Segmentation (D) is Correct

Network segmentation isolates the legacy system into a restricted zone or VLAN. By enforcing strict access control lists (ACLs) and limiting communication paths, segmentation reduces the attack surface. Even if the underlying protocol transmits cleartext, segmentation ensures that only authorized, trusted endpoints can reach the system, minimizing exposure.

Why Other Options Are Incorrect

  • Tokenization (A) replaces sensitive data with non-sensitive placeholders, primarily used for data at rest or regulatory compliance. It does not encrypt network packets, making it ineffective against transmission vulnerabilities.
  • Cryptographic downgrade (B) intentionally weakens encryption algorithms, which directly contradicts security objectives and increases susceptibility to decryption attacks.
  • Patch installation (E) is explicitly invalidated by the prompt’s statement that “no software updates... are available.” Selecting this option indicates overlooking explicit scenario constraints.

Community Consensus

Multiple candidates correctly identified CD, emphasizing that tunneling handles encryption while segmentation handles isolation. Some confusion arose regarding tokenization, but the consensus rightly prioritizes transport-layer security for active data transmission.

Official Reference

  • NIST SP 800-53 Rev. 5 - SC-8 (Transmission Confidentiality and Integrity)
  • Cisco Documentation - SSH Port Forwarding and Tunneling Guide
  • CompTIA Security+ SY0-701 Official Objectives 1.4 & 3.1

Exam Strategy

When a question explicitly rules out direct fixes like patching or protocol upgrades, immediately pivot to compensating controls such as network isolation, encryption overlays, or strict access policies. Always match the control to the specific data state mentioned in the scenario; use transport-layer solutions (tunnels, VPNs) for data in transit, and masking/tokenization for data at rest.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide