SY0-701 Question 300
Single answerVulnerability response and remediation: Patching , Insurance , Segmentation , Compensating controls , Exceptions and exemptionsA hospital's security team identifies a critical remote code execution vulnerability on a legacy radiology system. The vendor has not yet released a compatible patch, and taking the system offline would disrupt patient care. Cyber insurance is in place, but the risk committee requires immediate action to reduce exposure while the organization waits for a permanent fix. Which action is the BEST response?
- A
Rely on the cyber insurance policy to cover any losses until a patch is available
- B
Document a permanent exemption for the vulnerable system because it supports a critical medical function
- C
Isolate the radiology system on a restricted network segment and apply compensating controls such as tightly limited access rules and increased monitoring
- D
Delay remediation until the next scheduled maintenance window because unplanned changes introduce operational risk
Show answer and explanation
Correct answer: C
Explanation
The best answer is to segment the vulnerable asset and implement compensating controls. In real environments, especially healthcare and other operationally sensitive sectors, immediate patching is not always possible due to vendor dependencies, uptime requirements, or safety concerns. Security best practices support using network segmentation, access control restrictions, enhanced logging and monitoring, and other compensating controls to reduce risk until remediation can occur. Cyber insurance does not replace technical controls; it helps with financial recovery after covered events. Likewise, exceptions or exemptions should be governed by formal risk acceptance processes and should not be used as a justification for inaction. This reasoning is consistent with common guidance from NIST vulnerability and risk management practices, including risk-based remediation and the use of compensating safeguards when direct remediation is temporarily unavailable.
- A. Incorrect.
This is incorrect because cyber insurance is a financial risk-transfer mechanism, not a security control. Insurance may help offset certain costs after an incident, but it does not reduce the likelihood of exploitation or satisfy the need for immediate technical mitigation. A common misconception is treating insurance as a substitute for remediation.
- B. Incorrect.
This is incorrect because a permanent exemption is generally not appropriate for a critical, actively exposed vulnerability. Exceptions and exemptions should be formally documented, time-bound when possible, approved through risk management, and accompanied by compensating controls. Simply declaring the system exempt leaves the vulnerability unmitigated.
- C. Correct.
This is correct because when patching is not immediately possible, segmentation and compensating controls are appropriate vulnerability response measures. Restricting network access, limiting allowed communications, enforcing least privilege, and increasing monitoring can materially reduce the attack surface while maintaining business operations. This approach aligns with practical risk reduction until the vendor patch can be tested and deployed.
- D. Incorrect.
This is incorrect because delaying action solely to preserve a maintenance schedule is not the best response to a critical vulnerability on a high-value system. While change management matters, the organization should implement interim safeguards immediately if patching is unavailable. Waiting without mitigation leaves the system unnecessarily exposed.