220-1102 Question 458
Single answerEOLA small medical office uses several Windows 8.1 workstations to access patient scheduling and billing systems. One receptionist reports that her PC is still functioning normally, but the IT technician notices that the operating system is end-of-life (EOL). The office manager wants to keep using the system because replacing it is inconvenient. Which action should the technician recommend FIRST to best reduce organizational risk while maintaining compliance and security best practices?
- A
Upgrade the workstation to a supported operating system or replace the device if it cannot meet current OS requirements
- B
Install a third-party antivirus product and continue using Windows 8.1 as long as malware scans are clean
- C
Disable internet access for the receptionist but continue using the PC for local logins and daily business tasks indefinitely
- D
Increase the strength of the local account password and enable screen lock timeouts on the Windows 8.1 system
Show answer and explanation
Correct answer: A
Explanation
End-of-life means the vendor has stopped providing mainstream support, especially security updates. In A+ Core 2, technicians are expected to recognize that unsupported operating systems create significant risk and should be upgraded, replaced, or otherwise removed from production use. For systems handling sensitive or regulated information, continued use of an EOL OS can create compliance concerns in addition to security issues. Microsoft lifecycle guidance for Windows products identifies when support ends, and standard security best practices recommend running supported, patched operating systems. Compensating controls such as antivirus, strong passwords, or limited network access may reduce risk somewhat, but they do not eliminate the core issue that the platform is no longer receiving vendor security updates.
- A. Correct.
Correct. When an operating system has reached end-of-life, the vendor no longer provides regular security updates, which creates ongoing security and compliance risk. The best first recommendation is to move the system to a supported platform by upgrading the OS or replacing the hardware if it does not support a current version. This aligns with standard lifecycle management and security best practices.
- B. Incorrect.
Incorrect. Antivirus can help detect some threats, but it does not replace vendor security patches for an unsupported operating system. An EOL OS remains vulnerable to newly discovered exploits even if third-party antimalware is installed. This is a common misconception because endpoint protection is important, but it is not a substitute for a supported OS.
- C. Incorrect.
Incorrect. Isolating a system from the internet may reduce some exposure, but the scenario states the workstation is used for daily business tasks in a medical office, and the recommendation is about best reducing organizational risk while maintaining compliance and security best practices. Keeping an EOL system in production indefinitely is not the preferred solution, especially in an environment handling sensitive data.
- D. Incorrect.
Incorrect. Strong passwords and screen locks are useful security controls, but they do not address the central problem of an unsupported operating system. These controls help with unauthorized access but do not fix the absence of security patches, bug fixes, and vendor support.