What Is the Primary Security Risk of Legacy Systems in Production?
Which of the following is the most important security concern when using legacy systems to provide production service?
Community Votes
58% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of vulnerability management and risk prioritization, with the common trap being the focus on visible symptoms like insecure protocols rather than the underlying root cause: discontinued vendor support.
Legacy systems pose significant security risks due to their age and outdated architecture, but the most critical concern is the lack of vendor support. Community consensus confirms that without ongoing updates and patches, organizations cannot mitigate newly discovered vulnerabilities, making unsupported systems the highest priority risk.
Candidates frequently select 'Use of insecure protocols' because it directly relates to network traffic and encryption weaknesses; however, this is often a manageable symptom that can be mitigated through compensating controls like network segmentation or encrypted tunnels, unlike the unpatchable nature of unsupported software.
Community Discussion (20 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept
Legacy systems, often classified as End-of-Life (EOL) or End-of-Support (EOS), continue to operate in production environments despite being superseded by modern alternatives. While they may still function operationally, their continued use introduces severe security liabilities that must be evaluated through a risk-based lens.Why Option B is Correct
Lack of vendor support is the most critical security concern because it eliminates the ability to receive security patches, firmware updates, or hotfixes for newly discovered vulnerabilities. As noted by multiple candidates, unsupported systems leave known exploits permanently active, forcing organizations to rely entirely on compensating controls. Without a vendor to validate fixes or provide guidance, any breach or zero-day discovery remains unaddressed indefinitely.Why Other Options Are Incorrect
- Instability (A) refers to operational reliability and performance degradation, which impacts business continuity but is not primarily a direct security threat.
- Loss of availability (C) is a potential outcome of a successful attack or system failure, but it is a consequence rather than the root security concern itself.
- Use of insecure protocols (D) is a valid technical flaw, but candidates often overestimate its severity compared to patch dependency. As highlighted in the community discussion (comment #10), insecure protocols can frequently be mitigated through network-layer compensating controls such as firewalls, VLAN segmentation, or encrypted tunnels. However, these workarounds do not fix underlying operating system or application vulnerabilities caused by discontinued vendor support.
Exam Context
CompTIA Security+ heavily emphasizes risk management and mitigation techniques. When legacy systems cannot be replaced immediately, certification frameworks prioritize identifying the factor that prevents remediation. Recognizing that patching capability outweighs specific protocol weaknesses aligns with industry best practices and exam logic.Official Reference
Exam Strategy
When evaluating security risks for legacy or unsupported systems, always look for the root cause that prevents remediation. If an option addresses the inability to apply patches or receive security updates, it typically outweighs specific technical flaws that might be mitigated through compensating controls like firewalls or encryption.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →