A legacy IIS server has a critical unpatched remote code execution vulnerability, and the application team cannot take it offline for patching this week. Which compensating control best reduces exploitability while the fix is pending?
Select an answer to reveal the explanation.
Short Explanation
Think of segmentation like closing a door to a room you can't fix yet. You still have the problem, but you keep it from reaching the rest of the house. That is why restricting the vulnerable host is the compensating control here.
Full Explanation
When a critical vulnerability cannot be patched immediately, a compensating control should reduce the practical likelihood or impact of exploitation. Network segmentation does this by removing the vulnerable asset from broader reachability, so only explicitly allowed hosts, ports, and protocols can interact with it. That directly limits the attack surface even while the underlying flaw remains present. A web application firewall can help inspect application-layer traffic, but it is narrower than segmentation and may not stop non-web exploitation paths, protocol abuse, or traffic that bypasses the protected interface. Raising SIEM alerting sensitivity may improve detection speed, yet it does not reduce reachability or prevent an attacker from successfully exploiting the host. An authenticated rescan can confirm the finding, but verification is not mitigation; it leaves the vulnerable system exposed during the delay. Exam caveat: compensating controls must be evaluated against the actual exposure vector, not merely added because they sound defensive. Operational check: document the exact VLAN, ACL, or host firewall rule set that enforces the segmentation, then validate it from an untrusted host and a permitted host.