Case 0C1627 · GRC · L2 Practitioner
The Exception Nobody Renewed
Practise as: Incident drill
Live alertAn external attack surface scan finds an internet-facing Windows Server 2012 R2 host running the billing portal; its risk exception expired 14 months ago.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Assess exposure first: is it exploitable now? Check open ports, known exploited vulns (CISA KEV), and logs for compromise.
- Short-term: isolate behind VPN/WAF, add EDR and monitoring. 2012 R2 ESU patches end 13 Oct 2026, so plan to migrate or retire.
- Escalate to the business owner: renew the exception with a fresh risk rating and deadline, or fund the migration.
- Fix the process: exceptions register with auto-reminders and expiry that escalates rather than silently lapsing.
- Report it as a governance failure, not just a vuln: an expired exception means risk ran unaccepted for 14 months.
If the interviewer pushes back
- The owner says the vendor app only runs on 2012 R2 and migration takes a year. What compensating controls make that tolerable?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.