A hospital network has medical devices running legacy operating systems that cannot be patched. Which network architecture control BEST reduces the risk these devices pose?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because isolating unpatachable devices in a restricted VLAN with minimal firewall rules limits the blast radius if a device is compromised and reduces exposure to network-based attacks. B is wrong because legacy OS devices often cannot support modern antivirus agents.
Full explanation below image
Full Explanation
A is correct because isolating unpatachable devices in a restricted VLAN with minimal firewall rules limits the blast radius if a device is compromised and reduces exposure to network-based attacks. B is wrong because legacy OS devices often cannot support modern antivirus agents. C is wrong because enabling HTTPS only secures management traffic but does not isolate the devices from network-based attacks. D is wrong because MFA protects administrative access but does not address network-level exposure of the devices themselves.