Triage BoardGet the app

Concept · Prioritization and mitigation

Compensating controls when you can't patch

A compensating control is a different safeguard you put in place when the control you should have, usually the patch, can't be applied yet: segmentation, a web application firewall (WAF) rule, tighter access, extra monitoring. Objective 2.3 of the CySA+ CS0-004 exam lists exceptions and compensating controls together under mitigation, and questions expect both: a documented exception that accepts the gap for a set time, and a control that narrows it. The topic belongs to prioritization and mitigation.

  • Exam code CS0-004
  • Tickets here 8

Five words that get mixed up

Remediation
Removing the vulnerability: applying the patch, upgrading, or fixing the code or configuration.
Mitigation
Reducing the likelihood or impact while the vulnerability is still there. A compensating control is one form of it.
Exception
A documented, approved decision to leave a finding open for a stated period, with an owner and a reason.
Compensating control
An alternative safeguard that blocks or watches the same attack path the missing control would have covered.
Residual risk
What is left after the controls. Someone with the authority to accept it has to do so; risk responses explains accept, transfer, avoid and mitigate.

From "can't patch" to a defensible exception

  1. Name the inhibitor

    Objective 4.1 lists the usual ones: contracts, organizational governance, business-process interruption, degrading functionality, legacy and proprietary systems, and patch availability. How to report them is covered in vulnerability reporting.

  2. Trace the attack path

    Ask what the attacker needs: network reach, a crafted request, a feature that is switched on, valid credentials.

  3. Choose a control that cuts that path

    Pick from the table below. A control that cuts a different path does not count.

  4. Write the exception

    Owner, affected assets, the control in place, the residual risk and an expiry date.

  5. Validate the control

    Test it from the attacker's position, for example by rescanning from the segment it is meant to block.

  6. Patch when you can

    At expiry, fix the flaw or renew the exception on purpose. An exception that silently rolls over is a gap that nobody owns.

Match the control to the attack path

Common compensating controls and the gap each one leaves
If the exploit needsA control that cuts itWhat it leaves open
Network reach to a serviceSegmentation or an access list allowing named hosts onlyAn attacker already inside the allowed segment
A crafted web requestA WAF or intrusion prevention rule for that request pattern (a virtual patch)Variants the rule does not match
A feature that is switched onDisable the feature or service if the business can do without itSomeone re-enabling it during an upgrade
Valid credentials or an admin roleMultifactor authentication, removing standing admin rightsMisuse by people who keep access
Nothing you can blockExtra logging and an alert for the exploit's behaviorPrevention: monitoring only shortens time to detect

Two half-answersTrap

  • An exception with no control attached is plain risk acceptance. The exam wants the gap narrowed as well as recorded.
  • A control with no exception and no end date gets treated as the fix. The finding stays open until the patch goes in, and the report should say so.

Write the expiry date before you write the control.

Can't patch today

The systems described here can't take the fix today: some are legacy, some vendor-locked, some always on.

Ticket 1 / 8

0 right

INC-001

A highly privileged pod contains an unpatchable zero-day vulnerability. Which interim mitigation strategy most effectively contains this threat without taking the cluster offline?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AYou cannot patch a zero-day that has no fix, and changing the shared container runtime touches every workload on the node instead of containing one pod.
  2. BRestarting the pod after each detection brings back the same vulnerable image with the same privileges, so the exposure never goes away.
  3. CCorrect: a dedicated namespace with restrictive network policies cuts what the privileged pod can reach while the cluster keeps running, which is exactly what an interim compensating control is for.
  4. DMoving the container with identical permissions just relocates the risk to another cluster; nothing about its reach or privileges is reduced.

INC-002

What is the BEST approach for handling vulnerabilities in legacy systems that cannot be patched or upgraded?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AReplacing every legacy system regardless of business impact ignores cost and operational needs and is rarely possible right away.
  2. BCorrect: When a system cannot be patched, compensating controls such as network segmentation and closer monitoring reduce the risk while the system keeps running.
  3. CAccepting the risk with no further action leaves a known weakness exposed and skips the documented, mitigated exception that should go with it.
  4. DDisconnecting a system permanently may remove the risk, but it also removes the business function the system exists to provide.

INC-003

A vulnerability management team must address several newly discovered vulnerabilities. Based on the provided asset table, which system requires a compensating control rather than an immediate patch due to its business risk profile?

Exhibit

Asset NameCVE StatusCISA KEVPatch ImpactBusiness Criticality
Web-Srv-01CriticalListedRequires Service RestartLow (Dev Environment)
DB-Prod-01CriticalListedRequires Full OS RebootHigh (Zero Downtime SLA)
Mail-Edge-01HighNot ListedNo Reboot RequiredMedium (Tolerates Outage)
File-Share-02MediumNot ListedRequires Service RestartLow (Internal Only)

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AMail-Edge-01 needs no reboot and tolerates outages, so it can simply be patched.
  2. BCorrect: DB-Prod-01 has a KEV-listed critical CVE, but its patch needs a full OS reboot and the server has a zero-downtime SLA, so it needs a compensating control until the patch can be scheduled.
  3. CFile-Share-02 is a low-criticality internal system with a medium CVE, so a routine patch with a service restart is acceptable.
  4. DWeb-Srv-01 is a low-criticality dev server, so a service restart costs little and the KEV-listed CVE should be patched right away.

INC-004

Applicable federal guidance mandates immediate remediation of a KEV-listed vulnerability, but no stable vendor patch exists. How should the security team resolve this conflict while aligning with regulatory deadlines?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: When a KEV deadline arrives before a stable patch exists, applying mitigations and documenting the interim status is the accepted way to meet the remediation requirement.
  2. BWaiting for the vendor misses the deadline and leaves an actively exploited flaw exposed.
  3. CLowering the score in the scanner hides the risk instead of reducing it and falsifies the record.
  4. DPermanently decommissioning a critical asset is an extreme step when mitigations can bring the risk down.

INC-005

A system administrator disabled a specific CVE plugin in the vulnerability scanner because it repeatedly crashed a legacy application. Which of the following is the most appropriate alternative action to manage this risk?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ALowering the score to protect compliance metrics hides the risk and does nothing to reduce it.
  2. BCorrect: With the plugin disabled, the flaw is no longer tested, so the risk needs compensating controls such as segmentation, and the crash should be investigated so the check can be safely restored.
  3. CExcluding the whole subnet from scanning creates a much larger blind spot than the single disabled plugin.
  4. DHitting a fragile legacy application with an unauthenticated scan does not manage the risk and may crash it again.

INC-006

A vendor states a patch for a critical vulnerability will take six months. Which approach represents the best mitigation strategy for the affected workloads during this period?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AScanning more often only confirms the vulnerability again; it does nothing to reduce exposure for six months.
  2. BDecommissioning the application stops the business function, which is out of proportion when isolation can reduce the risk.
  3. CBeing unable to change vendor code does not justify accepting a critical risk with no mitigation.
  4. DCorrect: Isolating the affected workloads behind access controls is a compensating control that shrinks the attack surface until the patch ships.

INC-007

A legacy industrial control system runs an unpatchable operating system with multiple high-severity CVEs that have public exploits. The system cannot be taken offline without halting production. Which escalation and mitigation approach is most appropriate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Management has to own the decision, so the analyst escalates with the compensating controls in place (such as segmentation and monitoring) and a clear statement of the risk that remains.
  2. BThe OS cannot be patched, and forcing changes onto an ICS that must stay up risks halting production.
  3. CReplacement may be the long-term fix, but forcing it this quarter ignores production constraints and leaves the system exposed in the meantime.
  4. DHigh-severity CVEs with public exploits on a production ICS are not low-value findings and cannot be ignored.

INC-008

A vulnerable library in a web application allows remote code execution. Configuration changes alone cannot fully mitigate the flaw. Which remediation approach is required?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe stem already says configuration changes cannot fully fix the flaw, so editing config files and restarting leaves the vulnerable library in place.
  2. BWAF rules and segmentation can lower exposure for a while, but relying on them without ever patching turns a temporary compensating control into permanent residual risk.
  3. CTurning off the affected endpoints until a quarterly release may break business functions and still leaves the library unpatched for months.
  4. DCorrect: the real fix is to patch the library or change the code; a WAF rule only bridges the gap as a temporary compensating control until that fix ships.

Shift tally

0 / 0

Living with an open finding

If I add a compensating control, have I accepted the risk?

No. Acceptance leaves the risk as it is. A compensating control is mitigation: it reduces the risk, and the exception documents the residual part that someone accepts.

Which control type should I pick for a compensating control?

Any of them. Segmentation is technical, a stricter approval process is administrative, a locked cabinet is physical. The CS0-004 objectives sort controls by type and by function in objective 2.4, covered in controls and risk management.

Can I lower the CVSS score once a compensating control is in place?

It can change the Environmental metrics you set for your own copy of the score. If segmentation means the service is no longer reachable from the network at large, you can reflect that in the modified attack vector; the vendor's Base score stays the same. The CVSS v4.0 vs v3.1 guide explains who sets which group.

How long can I keep an exception open?

As long as the inhibitor lasts and no longer than your policy allows. The expiry date exists to force a decision: patch, replace the system, or renew the exception with fresh approval and a fresh look at the control.

Who signs off on the exception?

Someone with authority to accept the residual risk, usually the asset or business owner under your governance policy. The analyst who found the flaw documents it and recommends the control, but does not approve the exception alone.

Sources

  1. NIST, SP 800-40r4 Guide to Enterprise Patch Management Planning (checked October 9, 2026)
  2. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) · objectives 2.3 and 4.1 (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.