A plant historian in the OT network has a known critical vulnerability, but the vendor says no patch will be released and the asset cannot be taken offline. The vulnerability analyst needs to reduce risk now. Which action should be prioritized?
Select an answer to reveal the explanation.
Short Explanation
Think of an unpatched OT device like a locked door you can't replace: you can't fix the hardware, so you keep people from wandering near it. Segmenting it and watching who knocks is the practical move. Don't just accept the risk because maintenance is far off.
Full Explanation
Unpatched OT systems require compensating controls because patching is often unavailable, unsafe, or blocked by vendor constraints. The practical priority is to reduce exposure and detect exploitation: place the asset in a restricted OT segment, enforce least-privilege access, and monitor anomalous protocols or login attempts. This aligns with risk-based vulnerability management when remediation is impossible. Accepting the risk without compensating controls leaves the vulnerability exposed and fails the requirement to mitigate residual risk. Relying only on host-based firewall rules may be insufficient if the device cannot be hardened, if the OS is legacy, or if network-level segmentation is needed to contain lateral movement. Replacing the device may be the eventual lifecycle fix, but it is not the immediate prioritized action when the asset must remain online and budget or change control prevents rapid hardware swaps. Exam caveat: choose the action that reduces exposure now, not the action that merely documents or delays the issue. Operational check: confirm the OT asset's traffic is restricted to approved endpoints and that SIEM/EDR alerts exist for unexpected access or protocol anomalies.