Security Concerns with Legacy Systems in Production

Answer Correct answer: B — Lack of vendor support leaves legacy systems unable to receive critical security patches and updates for known vulnerabilities.

Which of the following is the most important security concern when using legacy systems to provide production service?

  1. Instability
  2. Lack of vendor support Correct Answer
  3. Loss of availability
  4. Use of insecure protocols

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the understanding that without vendor patches, legacy systems remain exposed to exploitable flaws indefinitely.

The most critical security risk of legacy systems is the lack of vendor support, which prevents patching known vulnerabilities. This page explains why unsupported systems pose a greater threat than instability or protocol usage.

Learners often choose Use of insecure protocols because they assume old tech is inherently unsafe, ignoring that active support is the primary defense against known exploits.

Community Discussion (4 comments)

AspiringNerd 👍 1 Selected: B
Def lack of vendor support.
shady23 👍 1 Selected: B
B. Lack of vendor support
salah112 👍 3 Selected: B
B. Lack of vendor support The most important security concern when using legacy systems to provide production services is often the lack of vendor support. Legacy systems, especially those that are no longer supported by vendors, may not receive security updates, patches, or bug fixes. This leaves them vulnerable to known security vulnerabilities that could be exploited by attackers
Hs1208 👍 1 Selected: B
B. Lack of Vendor support

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B. Lack of vendor support is the most important security concern because it means the organization cannot obtain official security patches or updates. Without these fixes, any discovered vulnerability remains permanently exploitable, creating a persistent risk vector.

Why the Other Options Are Wrong

Instability (A) and Loss of availability (C) are operational concerns rather than direct security vulnerabilities. While insecure protocols (D) are risky, many legacy systems can be secured via network segmentation or tunneling; however, the inability to patch the underlying OS or application due to lack of support is an unresolvable fundamental flaw.

Community Comment Notes

The community consensus strongly supports option B, highlighting that unsupported systems do not receive bug fixes. As salah112 noted, "Legacy systems... may not receive security updates... leaving them vulnerable." Other users like AspiringNerd confirmed this as the definitive lack of support issue.

Exam Strategy

When evaluating legacy systems, prioritize the ability to maintain and patch the system. If a vendor no longer supports the product, you lose the primary mechanism for addressing new threats, making it the highest priority security gap.

Frequently Asked Questions

Is using insecure protocols worse than no vendor support?

No. While insecure protocols are risky, they can sometimes be mitigated with network controls. Lack of vendor support means you cannot fix the root cause of vulnerabilities.

Does instability affect security more than availability?

Instability affects availability, but neither is a direct security vulnerability like an unpatched exploit. Security focuses on confidentiality, integrity, and protection from attacks.

Related Analysis

← Back to SY0-601 Study Guide