SY0-701 exam dumps

SY0-701 practice question 188 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 188

Single answerEmbedded systems

A hospital is deploying internet-connected infusion pumps across several patient care units. The pumps run a stripped-down embedded operating system, cannot support traditional endpoint security agents, and must remain available for patient safety. Security staff are concerned that if one pump is compromised, an attacker could use it as a foothold to reach clinical workstations and other medical devices. Which of the following is the BEST control to reduce this risk while maintaining pump availability?

  1. A

    Place the infusion pumps on a dedicated VLAN with tightly restricted ACLs that only allow required communications to approved management and monitoring systems

  2. B

    Install a host-based antivirus and EDR suite directly on each infusion pump to detect malware and lateral movement

  3. C

    Require clinicians to change the local administrator password on each pump every 30 days

  4. D

    Disable all network connectivity on the pumps so they cannot be reached by attackers

Show answer and explanation

Correct answer: A

Explanation

The best answer is network segmentation with restrictive ACLs because embedded systems frequently have limited security capabilities and high availability requirements. For medical and other embedded devices, organizations commonly rely on compensating controls such as isolation, allowlisting of network flows, jump servers, and continuous monitoring instead of installing full endpoint agents. This aligns with widely accepted security architecture principles such as least privilege, network segmentation, and defense in depth. In healthcare environments, guidance from NIST on IoT and device cybersecurity and general medical device security best practices emphasizes asset identification, segmentation, minimal services, and controlled communications to reduce exposure and contain compromise.

  • A. Correct.

    Correct. Embedded and medical devices often cannot run full endpoint protection or tolerate frequent software changes. Segmenting them onto a dedicated network and enforcing access control lists to permit only necessary traffic is a primary compensating control. This reduces the blast radius of a compromise, limits lateral movement, and helps preserve availability for safety-critical systems.

  • B. Incorrect.

    Incorrect. This is a common misconception based on traditional IT endpoints. Many embedded systems, including medical devices, lack the CPU, memory, storage, vendor support, or regulatory approval needed for host-based antivirus or EDR agents. Attempting to install unsupported security software could destabilize the device or void support agreements.

  • C. Incorrect.

    Incorrect. Password management can be important, but this does not best address the scenario's main risk: network-based pivoting from a compromised embedded device. In many embedded environments, local administrative access is limited, shared, vendor-controlled, or not frequently used by clinicians. Even strong password hygiene alone does not contain lateral movement across the network.

  • D. Incorrect.

    Incorrect. While removing network access would reduce exposure, it is not the best answer in this scenario because the pumps are described as internet-connected and are likely integrated with management, monitoring, update, or clinical systems. Eliminating connectivity may break required functionality and affect operations. Security+ typically emphasizes applying controls that reduce risk while supporting business and safety requirements.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam