SY0-701 exam dumps

SY0-701 practice question 91 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 91

Single answerEnd-of-life

A security administrator discovers that a business-critical file server is running an operating system version that reached end-of-life (EOL) six months ago. The vendor no longer provides security patches, but the application hosted on the server cannot be migrated for another four months due to a contractual dependency. Management wants to reduce risk immediately without disrupting operations. Which action is the BEST response?

  1. A

    Place the server on an isolated network segment with tightly restricted access and document a formal exception until it can be replaced

  2. B

    Keep the server in production as-is because compensating controls are unnecessary if antivirus is current

  3. C

    Upgrade only the server's antivirus signatures and defer all other changes until the migration project is complete

  4. D

    Disable system logging on the server to reduce performance impact and avoid drawing attention to known vulnerabilities

Show answer and explanation

Correct answer: A

Explanation

End-of-life systems present a significant security risk because the vendor no longer provides patches, bug fixes, or support. In a real-world Security+ context, the preferred action is to replace or upgrade the asset. If that cannot happen immediately, organizations should implement compensating controls to reduce risk, such as network segmentation, application allowlisting where feasible, restricted administrative access, enhanced logging and monitoring, vulnerability management tracking, and documented risk acceptance or exception handling. This aligns with common security best practices and guidance from organizations such as NIST, which emphasizes mitigating risk through defensive architecture, continuous monitoring, and formal risk management when unsupported assets must temporarily remain in service. The key concept is that EOL systems should not simply remain in place without additional controls; they should be isolated, monitored, and scheduled for replacement as soon as operationally possible.

  • A. Correct.

    Correct. When a system is at end-of-life, it no longer receives vendor security updates, creating ongoing exposure to known vulnerabilities. If immediate replacement is not possible, the best practice is to apply compensating controls such as network segmentation, strict ACLs, limiting inbound and outbound access, enhanced monitoring, and formal risk acceptance or exception documentation. This reduces the attack surface while maintaining business operations until decommissioning or replacement can occur.

  • B. Incorrect.

    Incorrect. Current antivirus alone does not adequately protect an EOL system because unsupported operating systems remain vulnerable to unpatched flaws at the OS and service level. This option reflects the common misconception that endpoint protection can fully compensate for missing vendor patches. In reality, unsupported systems require layered controls and a plan for replacement.

  • C. Incorrect.

    Incorrect. Updating antivirus signatures is helpful but insufficient. It addresses only one layer of defense and does not mitigate the fundamental risk of an unsupported platform with no security patch availability. Deferring all other action leaves the organization exposed to exploitation of known vulnerabilities for months.

  • D. Incorrect.

    Incorrect. Disabling logging would make the situation worse by reducing visibility, hindering incident detection, and weakening forensic capability. EOL assets generally require more monitoring, not less. Performance concerns do not outweigh the need for auditability and security oversight on a high-risk legacy system.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam