220-1102 Question 19
Single answerVendor life-cycle limitationsA small accounting firm is still using several Windows 8.1 workstations because a tax-preparation application has not yet been replaced. The PCs are connected to the internet and store client financial data. During a security review, a technician finds that the systems are no longer receiving security updates from the vendor. Which action is the BEST recommendation based on vendor life-cycle limitations?
- A
Keep the Windows 8.1 systems in production and rely on antivirus software to compensate for the missing vendor updates
- B
Upgrade the systems to a vendor-supported operating system, or isolate and plan replacement if the application prevents an immediate upgrade
- C
Disable the local firewall so the legacy application can communicate more easily while the systems remain in service
- D
Continue using the systems normally because unsupported operating systems can still be secure if users avoid suspicious websites
Show answer and explanation
Correct answer: B
Explanation
Vendor life-cycle limitations are an important A+ Core 2 topic because they directly affect security, supportability, and compliance. When an operating system or application reaches end of life or end of support, the vendor no longer provides regular security updates, bug fixes, or official support. For business systems that store sensitive information, the best practice is to upgrade to a supported product. If an immediate migration is not possible because of application compatibility, technicians should reduce exposure by isolating the system, limiting internet access, documenting the risk, and planning replacement. This aligns with common security best practices and vendor guidance from companies such as Microsoft, which publishes product life-cycle dates and support policies.
- A. Incorrect.
This is incorrect. Antivirus is only one layer of defense and does not replace vendor-provided security patches, bug fixes, and platform support. Once an operating system reaches end of support, newly discovered vulnerabilities may remain unpatched, creating significant risk, especially on internet-connected systems handling sensitive data.
- B. Correct.
This is correct. When a product has reached the end of vendor support, best practice is to move to a supported version or replacement platform. If a business dependency prevents an immediate upgrade, the legacy system should be isolated as much as possible and included in a documented replacement plan. This addresses the risk created by the vendor life-cycle limitation while supporting business continuity.
- C. Incorrect.
This is incorrect. Disabling the firewall reduces security further and does not address the real issue: the operating system is beyond vendor support. This option reflects a common but dangerous misconception that compatibility problems should be solved by weakening security controls.
- D. Incorrect.
This is incorrect. Safe browsing habits help reduce risk, but they do not eliminate exposure from unpatched operating system vulnerabilities. Unsupported systems remain a problem even with careful users because threats can arrive through email, websites, removable media, network services, or other compromised systems.