SY0-701 - Threats, Vulnerabilities, and Mitigations - Section 2.5

Explain the purpose of mitigation techniques used to secure the enterprise.

Describe how segmentation, hardening, patching, and access control each reduce the attack surface or limit the blast radius of a compromise. Choose the appropriate mitigation technique for a given threat, recognising that least privilege limits lateral movement while segmentation contains an active breach.

segmentationhardeningleast privilegepatchingaccess control

Practice question for this objective

Free sampleThreats, Vulnerabilities, and Mitigationsmedium

Which statement best describes how segmentation, hardening, least privilege, and patching together reduce the impact of a compromised endpoint?

  • AHardening removes unnecessary functionality, patching closes known flaws, least privilege limits what the compromised account can do, and segmentation limits where the compromise can reach. Correct
  • BPatching guarantees that no compromise can occur, so the other three controls are redundant on a fully patched estate that follows vendor advisories.
  • CSegmentation alone is sufficient because confining a compromised endpoint to a single VLAN prevents any further harm without the need for host-level controls.
  • DLeast privilege addresses both attack surface and lateral movement, so segmentation and hardening primarily provide audit benefits rather than risk reduction.
Explain how segmentation, hardening, least privilege, and patching layer to reduce both the likelihood and the impact of endpoint compromise. Defence in depth assumes that any single control can fail. Hardening shrinks the attack surface of each host, patching removes known exploit paths, least privilege limits the authority of any compromised identity, and segmentation constrains the reachability of any compromised host. Removing any one layer leaves a predictable gap, and overstating the strength of any one layer leads to single points of failure in the mitigation strategy.

Why A is correct: Each control addresses a different dimension of risk, and together they reduce both the likelihood and the blast radius of a compromise in a defence in depth pattern.

Why B is wrong: Patching only addresses known flaws and cannot prevent zero day or credential-based compromise, so layered controls are still required even on a well patched estate.

Why C is wrong: Segmentation contains reachability but does not stop damage within the segment, and an isolated host with weak privileges and unpatched software can still be abused against assets it can reach.

Why D is wrong: Least privilege limits authority but does not reduce host attack surface or restrict network reachability, and treating segmentation and hardening as audit aids understates their preventive value.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Threats, Vulnerabilities, and Mitigations objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.