Security Implications of End-of-Life Operating Systems

Architecture and Design

A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?

  1. Patch availability Source Reference Answer
  2. Product software compatibility
  3. Ease of recovery
  4. Cost of replacement

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the understanding that EOL status directly correlates with no more security patches, distinguishing this technical constraint from business factors like cost or compatibility.

Using end-of-life (EOL) operating systems poses a critical security risk due to the cessation of vendor support. The primary security implication documented by security teams is the lack of patch availability for known vulnerabilities.

Candidates may incorrectly select 'Cost of replacement' because it is a significant business concern; however, the question specifically asks for a 'security implication,' which excludes financial considerations.

Community Discussion (4 comments)

SHADTECH123 👍 7 Selected: A
The most likely security implication that the security team would document is patch availability. End-of-life operating systems no longer receive security updates or patches from the vendor, which leaves them vulnerable to newly discovered exploits and vulnerabilities. This lack of ongoing support means that any security flaws found in the operating systems will not be addressed, increasing the risk of compromise.
Etc_Shadow28000 👍 6 Selected: A
A. Patch availability The primary security implication of using end-of-life operating systems is the lack of patch availability. End-of-life systems no longer receive security updates or patches from the vendor, making them vulnerable to known exploits and security vulnerabilities that will not be fixed. This poses a significant risk to the security of the kiosks and the overall network. Therefore, the correct answer is: A. Patch availability
9149f41 👍 2 Selected: A
The question is not asking for a solution to the legacy system, but rather asking what information needs to be documented in this scenario. Additionally, determining replacement costs is not a cybersecurity responsibility, as security teams can only recommend replacement while vendors provide the actual cost estimates
dbrowndiver 👍 1 Selected: A
Patch availability is a critical concern for maintaining the security and integrity of systems. The absence of patches for EOL systems is a major security risk that the security team would likely document as a primary concern

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Selecting 'Patch availability' is correct because end-of-life (EOL) operating systems no longer receive security updates or hotfixes from the vendor. Without these patches, any newly discovered vulnerabilities remain unaddressed, leaving the kiosks and the network exposed to exploitation. This is a direct security implication that a security team must document to justify remediation efforts.

Why the Other Options Are Wrong

'Product software compatibility' (B) is a functional issue, not primarily a security one. 'Ease of recovery' (C) relates to disaster recovery planning rather than the inherent risk of the OS state. 'Cost of replacement' (D) is a financial or administrative consideration; while important for budgeting, it is not a security implication in the context of vulnerability management.

Community Comment Notes

Community comments consistently highlight that EOL means no more security updates. One comment notes that determining replacement costs is outside the cybersecurity team's primary responsibility, reinforcing why D is incorrect. Another emphasizes that the question asks for documentation of the security implication, not a solution or business metric.

Exam Strategy

When asked for a 'security implication,' always filter out non-security factors like cost, convenience, or general functionality. Focus on risks related to confidentiality, integrity, and availability, such as unpatched vulnerabilities, weak encryption, or lack of access controls.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide