How should unused, non-compliant desktops be handled on a network?

A security administrator notices numerous unused, non-compliant desktops are connected to the network. Which of the following actions would the administrator most likely recommend to the management team?

  1. Monitoring
  2. Decommissioning Source Reference Answer
  3. Patching
  4. Isolating

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests asset lifecycle management and risk reduction; the trap is choosing a reactive fix like isolating or patching instead of eliminating the unnecessary asset.

For unused, non-compliant desktops, the correct step is decommissioning (option B) to reduce the attack surface. The community strongly favors B over isolating or patching.

Choosing D. Isolating, because it appears to secure non-compliant devices; however, isolation still leaves the device connected and requires ongoing management, while decommissioning permanently removes the risk.

Community Discussion (3 comments)

qacollin 👍 6 Selected: B
Decommissioning unused and non-compliant desktops will reduce security risks by removing potential points of vulnerability from the network. This action helps to ensure that only compliant and necessary devices are connected, maintaining the integrity and security of the network.
viktorrdlyi 👍 1 Selected: B
Decommissioning
fmeox567 👍 1 Selected: D
The correct answer is: D. Isolating GPT

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B, Decommissioning, is correct because these desktops are both unused and non-compliant. Unused assets provide no organizational benefit, and non-compliance creates security risk; removing them shrinks the attack surface. This aligns with proper asset management and lifecycle procedures, as noted in the top community comment (likes=6), which states decommissioning reduces security risks and ensures only compliant, necessary devices remain.

Why the Other Options Are Wrong

A. Monitoring would never fix non-compliance; it only observes. C. Patching might address non-compliance but is wasted effort on unused machines, and not all non-compliance is patching. D. Isolating (the GPT-generated comment) could contain threats, but it does not eliminate the risk or reduce management overhead; the question specifically says 'unused,' making decommissioning the most appropriate recommendation.

Community Comment Notes

The community overwhelmingly chose B (88 votes) with only one anonymous comment suggesting D. The useful comment by 'Dec' correctly connects decommissioning to security risk reduction and network integrity. The D comment lacks substantive reasoning and contradicts both the scenario and the majority consensus.

Official Reference

Exam Strategy

On Security+ questions, prioritize permanently eliminating risk over temporary mitigation. If the question says a device is 'unused,' look for decommissioning rather than patching or isolating, which leave the asset in place and require continued attention.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide