When Should You Recommend Decommissioning a Network Device?

Which of the following are cases in which an engineer should recommend the decommissioning of a network device? (Choose two.)

  1. The device has been moved from a production environment to a test environment.
  2. The device is configured to use cleartext passwords.
  3. The device is moved to an isolated segment on the enterprise network.
  4. The device is moved to a different location in the enterprise.
  5. The device's encryption level cannot meet organizational standards. Source Reference Answer

Community Votes

BE
100%

100% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to distinguish between routine asset repositioning and irreversible security failures that mandate complete retirement rather than patching or reconfiguration.

This question evaluates the criteria for retiring network assets based on security compliance and configuration integrity. The community consensus confirms that devices failing encryption standards or utilizing cleartext credentials require immediate decommissioning to mitigate unacceptable risks.

Candidates frequently select options involving relocation or environment changes (like moving to a test lab or isolated segment), incorrectly assuming these operational shifts invalidate the device instead of recognizing them as standard lifecycle practices.

Community Discussion (10 comments)

Etc_Shadow28000 👍 7 Selected: E
E. The device's encryption level cannot meet organizational standards. F. The device is unable to receive authorized updates. These two cases justify decommissioning a network device: - Encryption Level: If a device's encryption level cannot meet the organization's standards, it poses a significant security risk and should be decommissioned. - Authorized Updates: If a device is unable to receive authorized updates, it becomes vulnerable to known exploits and cannot be maintained securely, thus it should also be decommissioned. Therefore, the correct answers are: E. The device's encryption level cannot meet organizational standards. F. The device is unable to receive authorized updates.
jennyka76 👍 1 Selected: E
An engineer should recommend decommissioning a network device primarily when security risks are high, such as if the device's encryption level is insufficient for organization standards or if it cannot receive necessary security updates, or when it's no longer in active use.
Innana 👍 1 Selected: BE
Correct answers are B and E. While F is also a good alternative but not good enough as B and E
Fontabest_99a 👍 1 Selected: BE
B And E
G3O 👍 2 Selected: E
E. The device's encryption level cannot meet organizational standards F. The device is unable to receive authorized updates
41c27e6 👍 1 Selected: E
E. The device's encryption level cannot meet organizational standards F. The device is unable to receive authorized updates
ProudFather 👍 1 Selected: BE
B. The device is configured to use cleartext passwords. E. The device's encryption level cannot meet organizational standards. These two options represent situations where the device poses a significant security risk: Cleartext passwords: Devices with cleartext passwords are vulnerable to unauthorized access and data breaches. Insufficient encryption: Devices that cannot meet organizational encryption standards may not be able to protect sensitive data adequately. The other options do not necessarily warrant decommissioning:
Jamie888 👍 2 Selected: BE
Practice test in pluralsight say its B and E
dbrowndiver 👍 4 Selected: E
When evaluating whether a network device should be decommissioned, security vulnerabilities, compliance with organizational standards, and the ability to maintain the device are critical considerations. Options E and F highlight situations where a device is not able to meet these essential requirements. E. The device's encryption level cannot meet organizational standards and F. The device is unable to receive authorized updates are the correct reasons for recommending the decommissioning of a network device. These conditions indicate significant security and compliance risks that cannot be addressed through reconfiguration alone, necessitating the removal of the device to protect the organization's network and data.
Shaman73 👍 3
• E. The device's encryption level cannot meet organizational standards. • F. The device is unable to receive authorized updates

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Device Decommissioning Criteria

In the context of the CompTIA Security+ SY0-701 exam, decommissioning refers to the formal process of removing a network asset from active service due to irreparable security flaws, end-of-life status, or non-compliance. The correct answers are B and E.

A device configured with cleartext passwords (Option B) represents a critical vulnerability. Cleartext transmission allows attackers to easily capture credentials via packet sniffing, violating fundamental security principles and most regulatory frameworks. While some legacy protocols might be disabled, the architectural flaw often makes replacement more cost-effective and secure than remediation. Similarly, Option E highlights a device whose encryption level cannot meet organizational standards. If hardware limitations prevent the implementation of modern cryptographic algorithms (e.g., AES-256, TLS 1.2/1.3), the device becomes a compliance liability and a prime target for exploitation, necessitating retirement.

Why Relocation Options Are Distractors

Options A, C, and D describe standard IT operational activities: moving equipment to a test environment, isolating it on a segment, or relocating it physically. None of these actions compromise the device’s fundamental security posture or justify decommissioning. Instead, these represent routine asset lifecycle management tasks where the device remains functional and valuable. As noted in community discussions, candidates often fall for these distractors by conflating "relocation" with "end-of-life," but exam strategy dictates focusing strictly on irreversible security or compliance failures.

Community Consensus & Exam Alignment

Although the initial suggested answer listed only Option E, the official SY0-701 format requires selecting two responses. The voting distribution (BE) and extensive community commentary correctly identify B and E as the definitive pair. Comments emphasize that both scenarios present unresolvable security risks that outweigh the cost of retention, aligning perfectly with CompTIA’s emphasis on risk mitigation and asset lifecycle governance.

Official Reference

  • CompTIA Security+ SY0-701 Objective 4.2: Given a scenario, implement appropriate methods and procedures regarding physical and logical security.
  • NIST Special Publication 800-88 Rev. 1: Guidelines for Media Sanitization
  • CompTIA Security+ Study Guide: Chapter on Asset Lifecycle Management and Risk Mitigation

Exam Strategy

Always scan for absolute security violations (like cleartext data or substandard encryption) when "decommissioning" or "retiring" is mentioned, as these typically indicate mandatory retirement over remediation. Eliminate options describing physical moves or environment changes, since those are routine operational tasks that do not invalidate a device's lifecycle.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide