Q: 13
Which of the following would most likely prevent exploitation of an end-of-life, business-critical system?
Options
Discussion
I don’t think it’s D. B fits better-encryption (D) can protect the data, but it doesn’t actually prevent exploitation if the system is still exposed. Isolation (B) cuts off access and really limits attack vectors, especially since you can't just decommission a business-critical setup here. Pretty common trap to pick encryption when isolation is the real preventative here.
Option D looked right to me since encryption can help protect data even on legacy systems. Had something like this in a mock, and they called out encryption as a control for old servers. But not totally sure if that's enough by itself.
C vs B, but pretty sure B fits best here. Isolation keeps the unpatchable system away from threats, especially since you can't just turn it off. Monitoring is useful but doesn't actually stop attacks upstream. Open to reasons for going C though.
B
B , because if the system is end-of-life and can’t be patched or turned off, isolation is your only real shot at stopping exploitation. Monitoring just tells you after something happens, doesn’t actually block anything. If system wasn’t business-critical, decommissioning (C) would work. Disagree?
If the requirement said "first step" instead of "most likely," would you still pick B or go for monitoring?
Be respectful. No spam.