Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?
Choose an answer
Tap an option to check your answer.
Correct answer: Compensating control.
Why this is the answer
A compensating control is an alternative security measure that mitigates the risk associated with a weakness when it's impractical or impossible to implement a primary control. In this scenario, a legacy Linux system might not support modern security features or updates, making it vulnerable. The host-based firewall, configured to restrict access to specific internal IP addresses, acts as a compensating control by reducing the attack surface and limiting potential exploitation, thereby addressing the risk posed by the legacy system's limitations. Network segmentation involves dividing a network into smaller, isolated segments, which is a broader architectural control, not specifically demonstrated by a single host-based firewall. Transfer of risk involves shifting the financial burden of risk, often through insurance, which is not a technical control. SNMP traps are alerts generated by network devices, not a security control in themselves.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed