SY0-701 exam dumps

SY0-701 practice question 72 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 72

Single answerUnsupported systems and applications

A manufacturing company relies on a legacy quality-control application that only runs on Windows 7. The software vendor no longer supports the application, and the operating system is also end-of-life. The workstation must remain online to send inspection results to an internal database, but recent vulnerability scans show multiple unpatched critical findings on the host. The security administrator cannot replace the application for at least six months. Which action should the administrator take FIRST to most effectively reduce risk while maintaining business operations?

  1. A

    Place the workstation in a restricted network segment with tightly limited firewall rules and allow only the specific communications required for the application

  2. B

    Install a host-based antivirus product and continue normal network access because malware protection compensates for missing patches

  3. C

    Disable logging on the workstation to improve performance and reduce the likelihood of attackers detecting defensive controls

  4. D

    Allow users to access the workstation remotely over RDP from any internal subnet so support staff can respond more quickly to issues

Show answer and explanation

Correct answer: A

Explanation

The best first step is to apply compensating controls that reduce exposure while preserving the required business function. For unsupported systems and applications, organizations should assume that vulnerabilities may remain unpatched indefinitely. Security best practices recommend isolating such assets, minimizing allowed network flows, restricting administrative access, and increasing monitoring until the system can be upgraded or retired. This aligns with common guidance from NIST, including concepts in NIST SP 800-40 on patch and vulnerability management and NIST SP 800-82 for protecting operational and legacy systems where patching may be limited. In practical Security+ terms, unsupported systems should be segmented, access should follow least privilege, and replacement planning should be documented as part of risk treatment.

  • A. Correct.

    Correct. When a system and application are unsupported and cannot be patched, the best immediate compensating control is to isolate the asset and strictly limit its communications. Network segmentation, access control lists, and host/network firewall rules reduce the attack surface while allowing only required traffic to the internal database or other necessary services. This is a standard risk-reduction approach for legacy and end-of-life systems that must remain operational.

  • B. Incorrect.

    Incorrect. Antivirus can help detect some malware, but it does not remediate the core problem of known, unpatched vulnerabilities in unsupported software. Treating endpoint protection as a substitute for security updates is a common misconception. Unsupported systems require compensating controls such as segmentation, restricted access, and close monitoring.

  • C. Incorrect.

    Incorrect. Disabling logging weakens security and incident response. Unsupported systems should typically receive more monitoring, not less, because they present elevated risk. Someone might choose this option thinking performance is the priority, but removing logs makes detection and forensic investigation significantly harder.

  • D. Incorrect.

    Incorrect. Broad RDP access increases exposure and creates additional attack paths to a high-risk legacy system. Remote administration, if required, should be tightly restricted through jump hosts, management networks, MFA where possible, and limited source IPs, not opened broadly across internal subnets.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam