ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization's legacy billing application runs on an unsupported operating system that cannot receive vendor patches. To meet the baseline requirement for timely patching, which compensating control would most closely satisfy the security objective while allowing the system to remain operational?
Enforce a 30-day user password rotation policy for all application users.
Configure automatic log deletion after seven days to prevent disk exhaustion.
Extend the vulnerability scanning schedule from weekly to quarterly to minimize system downtime.
Place the server on an isolated network segment with restrictive firewall rules that allow only required application traffic.
When a system cannot be patched, the goal is to reduce the likelihood that unpatched vulnerabilities can be reached or exploited. Isolating the server on its own network segment and enforcing strict firewall rules limits the attack surface and prevents unnecessary traffic from reaching the vulnerable host, providing a level of protection comparable to timely patching. Adjusting scan frequency, changing password rotation intervals, or shortening log retention do not directly mitigate exposure created by missing patches and therefore do not satisfy the intended security objective.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'network segmentation' mean in cybersecurity?
Open an interactive chat with Bash
Why are firewall rules important for isolated segments?
Open an interactive chat with Bash
How does reducing 'attack surface' help in cybersecurity?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .