N10-009 Question 196
Select 2A company is preparing for a security audit and discovers that several branch-office routers are still in production even though the model reached end-of-life (EOL) last year. The vendor portal shows the routers are now end-of-support (EOS), and no new security patches or firmware updates will be released. The routers currently function normally, but recent vulnerability notices affect similar platforms. The network administrator must reduce risk while maintaining business operations and follow proper life-cycle management practices. Which TWO actions should the administrator take first?
- A
Create a replacement plan for the EOS routers and schedule migration to supported hardware
- B
Keep the routers in service as long as they are stable because EOL and EOS do not affect security
- C
Review the current OS and firmware versions, document exposure, and assess compensating controls until replacement occurs
- D
Perform a factory reset immediately to return the routers to a secure default state
- E
Decommission the routers by disposing of them as e-waste now, even though they are still providing production connectivity
Show answer and explanation
Correct answers: A, C
Explanation
The best first actions are to plan replacement and assess interim risk. In life-cycle management, EOL generally indicates the product is no longer sold or is nearing retirement, while EOS means vendor support has ended, including patches, bug fixes, and often firmware or OS maintenance. From a Network+ perspective, this creates both security and operational concerns because unsupported infrastructure cannot be reliably remediated when vulnerabilities are discovered. Best practice is to inventory affected assets, confirm software and firmware status, document business impact, apply compensating controls where possible, and schedule migration to supported platforms. After migration, the organization should decommission the old routers properly by backing up any needed configurations, sanitizing stored data or credentials, removing them from asset inventories and monitoring systems, and disposing of them according to organizational policy and e-waste requirements. These actions align with common vendor life-cycle guidance and standard security frameworks that emphasize patch management, supported software, risk assessment, and controlled decommissioning.
- A. Correct.
Correct. Once hardware is EOS, the vendor no longer provides patches, bug fixes, or technical support, which increases operational and security risk. A core life-cycle management action is to plan and execute replacement with supported equipment. This is the most sustainable and audit-friendly response because it restores the ability to receive future OS and firmware updates.
- B. Incorrect.
Incorrect. This reflects a common misconception. Devices can continue operating after EOL or EOS, but stability does not mean they are secure or supportable. Without vendor patches or bug fixes, newly discovered vulnerabilities may remain permanently unaddressed, which is a significant risk in production environments.
- C. Correct.
Correct. Before replacement is complete, the administrator should verify the currently installed OS and firmware, determine whether the devices are already on the latest available release, document the risk, and implement compensating controls such as tighter ACLs, segmentation, management-plane restrictions, or enhanced monitoring. This is a practical interim step aligned with risk management and change-control best practices.
- D. Incorrect.
Incorrect. A factory reset does not resolve the underlying issue of EOS status or unavailable security updates. It may also erase required production configuration and cause an outage. Default settings are not inherently more secure, especially if the platform still cannot receive vendor fixes.
- E. Incorrect.
Incorrect. Proper decommissioning should occur only after services have been migrated off the devices. Immediate disposal while the routers still provide production connectivity would create unnecessary downtime. Decommissioning is the final stage of the life cycle, not the first response while the equipment is still needed.