SY0-701 exam dumps

SY0-701 practice question 71 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 71

Single answerUnsupported systems and applications

A hospital's radiology department relies on a legacy imaging workstation that runs an operating system and vendor application that are both end-of-support. The device cannot be upgraded because the imaging software is tied to specialized hardware, and replacing the system will take six months due to regulatory validation requirements. The security team is concerned about unpatched vulnerabilities but the workstation must remain operational for patient care. Which of the following is the BEST way to reduce risk during the interim?

  1. A

    Place the workstation on a dedicated network segment with strict firewall rules, allow only required communication paths, and closely monitor it for suspicious activity

  2. B

    Install a freeware antivirus product and allow the workstation to remain on the general user VLAN so staff can access it easily

  3. C

    Disable local logging to preserve system performance and rely on the workstation user to report anything unusual

  4. D

    Expose the workstation directly to the internet so the vendor can remotely troubleshoot issues faster

Show answer and explanation

Correct answer: A

Explanation

The best answer is to apply compensating controls because the core problem is an unsupported operating system and application that cannot be patched immediately. In real environments, especially healthcare, industrial, and other specialized systems, replacement may be delayed by operational or regulatory constraints. Security best practices in these cases emphasize isolating the asset, minimizing allowed communications, restricting administrative access, monitoring for indicators of compromise, and documenting the risk through the organization's risk management process. This aligns with common guidance from NIST, including the Cybersecurity Framework's protective and detective controls and NIST SP 800-40 guidance on patch management, which recognizes that when patching is not possible, organizations should use alternative mitigations such as network isolation and access restrictions. Security+ expects candidates to recognize that unsupported systems should be contained and monitored rather than treated like normal endpoints.

  • A. Correct.

    Correct. When a system or application is unsupported and cannot be patched, compensating controls are the most appropriate risk-reduction measure. Network segmentation, restrictive access control lists or firewall rules, and continuous monitoring reduce the attack surface and help contain compromise. This approach is practical for legacy operational and medical environments where replacement is delayed but availability is critical.

  • B. Incorrect.

    Incorrect. Antivirus may provide some value, but it is not sufficient as the primary control for an unsupported system with known unpatched vulnerabilities. Keeping the device on the general user VLAN increases exposure to malware, lateral movement, and unauthorized access. Ease of access for staff should not outweigh the need for containment.

  • C. Incorrect.

    Incorrect. Disabling logging weakens detection and incident response, which is especially dangerous for high-risk legacy systems. Unsupported devices should generally have increased monitoring, not less. Relying on end users to notice suspicious behavior is not an effective security control.

  • D. Incorrect.

    Incorrect. Direct internet exposure would significantly increase risk by making the unsupported system reachable by external attackers. If vendor access is required, it should be tightly controlled through secure remote-access methods, jump boxes, VPNs, and explicit allowlisting rather than open internet exposure.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam