2.5 Explain the purpose of mitigation techniques used to secure the enterprise

Domain 2: Threats, Vulnerabilities, and Mitigations

Mitigation techniques are the countermeasures side of Domain 2: segmentation, access control (ACLs, permissions), application allow lists, isolation, patching, encryption, monitoring, least privilege, configuration enforcement, and decommissioning. Hardening gets its own sub-list — encryption, endpoint protection, host-based firewalls, HIPS, disabling unused ports and protocols, changing default passwords, and removing unnecessary software. The exam asks which technique addresses a stated problem: default credentials on an appliance call for changing default passwords; malware spreading laterally calls for segmentation; an unmanageable legacy server calls for isolation or decommissioning. Distinguish allow lists (only approved software runs) from deny lists, and least privilege (rights limited to job needs) from need-to-know. Isolation and segmentation look similar but differ in degree — segmentation restricts traffic between zones, isolation removes connectivity entirely. Expect at least one question where patching is unavailable and a compensating mitigation like isolation is the correct choice.

What you must know

common pitfall · Candidates pick patching by reflex even when the scenario says the system cannot be patched, missing that isolation or a compensating control is the intended answer.

Try a sample question

Following a ransomware incident, forensics show the malware spread unimpeded from one infected laptop to file servers and workstations across a flat internal network. Management asks which mitigation techniques would BEST limit this kind of lateral movement in the future. (Select TWO.)

  • A Extending password expiration intervals
  • B Publishing an acceptable use policy
  • C Segmenting the network into isolated zones with restricted inter-zone traffic
  • D Enabling full-disk encryption on all laptops
  • E Applying least privilege so accounts and hosts reach only required resources
Show answer & explanations
  • A Extending password expiration intervals changes how often users rotate credentials; it has no bearing on malware that spreads by exploiting open network paths and accessible shares.
  • B An acceptable use policy sets behavioral expectations for employees, but it is an administrative document and provides no technical barrier against malware traversing the network.
  • C correct ·Correct. Segmentation breaks a flat network into isolated zones with controlled inter-zone traffic, so a compromise in one zone cannot freely reach servers and workstations in others.
  • D Full-disk encryption protects data at rest if a device is lost or stolen; on a running, unlocked system it does nothing to stop malware spreading over the network.
  • E correct ·Correct. Least privilege restricts what each account and host can access, shrinking the set of shares and systems ransomware can reach from any single compromised machine.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 2.5 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free