Which of the following will inhibit remediation when attempting to resolve a vulnerability?
Legacy systems commonly inhibit vulnerability remediation because they may depend on obsolete operating systems, unsupported applications, specialized hardware, outdated protocols, or vendor products for which security updates are no longer provided. Even when a vulnerability is accurately identified, the organization may be unable to apply a modern patch without breaking compatibility, interrupting a critical business process, or violating vendor support requirements.
NIST guidance explicitly recognizes that legacy systems create unique security-management challenges, while federal cybersecurity guidance warns that products remaining in service after vendor support ends may lack effective mechanisms for addressing newly discovered vulnerabilities.
In such circumstances, vulnerability-management teams may need to use compensating controls such as segmentation, firewall restrictions, application allowlisting, stronger access controls, enhanced monitoring, or service isolation while planning migration or replacement. These controls reduce exposure but do not remove the underlying software defect.
''Controlled systems,'' ''shared systems,'' and ''closed systems'' do not inherently prevent remediation. A shared system may require greater coordination, but it can still be fully supported and patchable. The defining issue with legacy technology is that technical and vendor constraints can directly prevent normal remediation.
Study Guide Reference: Vulnerability Management Remediation Constraints Legacy Systems End-of-Life Technology Patch Availability Compensating Controls System Replacement.
Currently there are no comments in this discussion, be the first to comment!