A critical remote code execution vulnerability is found on an unsupported legacy server, and the vendor cannot provide a patch. Which action should the analyst recommend first?
Select an answer to reveal the explanation.
Short Explanation
When a patch cannot be applied, you need a compensating control that reduces exposure while the primary fix is unavailable. Think of it like locking a door you cannot repair — segmentation and inbound restrictions keep attackers from reaching the vulnerable service. The trap is treating scans, signatures, or paperwork as substitutes for reducing attack surface.
Full Explanation
Compensating controls are alternative safeguards used when a primary control, such as a vendor patch, cannot be implemented. In this case, microsegmentation and restrictive inbound firewall rules reduce the likelihood that an unpatched remote code execution flaw is exploited by limiting which hosts can communicate with the vulnerable service. Risk acceptance is inappropriate as a first action because it transfers residual risk rather than reducing exposure, and it should follow a documented business decision after alternatives are evaluated. Repeated vulnerability scanning confirms the finding but does not mitigate it; scanning is detection, not a substitute for access control. Endpoint signature updates or YARA rules may support detection after compromise, but they do not prevent network exploitation of the service in the same way that restricting reachable paths does. Exam caveat: CompTIA often expects the analyst to identify the control that most directly reduces risk when remediation is impossible. Operational check: Validate the proposed segmentation by attempting a connection from an unauthorized host and confirming it is denied before submitting the change request.