Sometimes the right fix for a vulnerability cannot be applied. A medical device may be certified only with a specific operating system version, an industrial controller may need a plant shutdown to update, a vendor may no longer support a product, or a patch may break a critical application. In these cases you still have to manage the risk, and CySA+ tests how you do it: with compensating controls, segmentation and a documented exception.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.