Legacy systems present a significant security problem because they frequently cannot support current operating systems, security agents, encryption mechanisms, authentication controls, or vendor patches. When a business-critical legacy system cannot be remediated normally, strong network segmentation becomes an important compensating control. The objective is to reduce the system's reachable attack surface and restrict which users, hosts, protocols, and applications can communicate with it.
A segmented legacy asset might be placed in a dedicated VLAN or security zone and protected through restrictive firewall access-control rules, jump hosts, allowlisting, enhanced logging, and continuous monitoring. Even though segmentation does not remove the underlying vulnerability, it decreases exposure and makes exploitation or lateral movement considerably more difficult.
Degraded functionality is generally an effect or remediation constraint rather than the strongest reason for isolation. Asset obfuscation does not provide reliable security because hidden systems can still be discovered through enumeration or traffic analysis. A proprietary server is not automatically vulnerable merely because its implementation is proprietary; it may still support modern patches and security controls.
CS0-004 specifically covers segmentation as a vulnerability-scanning consideration, compensating controls as a mitigation strategy, and legacy systems as an important inhibitor to remediation.
Study Guide Reference: Vulnerability Management → Vulnerability Prioritization and Mitigation → Compensating Controls → Segmentation → Legacy-System Constraints.