Security Implications of End-of-Life Operating Systems
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the understanding that EOL status directly correlates with no more security patches, distinguishing this technical constraint from business factors like cost or compatibility.
Using end-of-life (EOL) operating systems poses a critical security risk due to the cessation of vendor support. The primary security implication documented by security teams is the lack of patch availability for known vulnerabilities.
Candidates may incorrectly select 'Cost of replacement' because it is a significant business concern; however, the question specifically asks for a 'security implication,' which excludes financial considerations.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Selecting 'Patch availability' is correct because end-of-life (EOL) operating systems no longer receive security updates or hotfixes from the vendor. Without these patches, any newly discovered vulnerabilities remain unaddressed, leaving the kiosks and the network exposed to exploitation. This is a direct security implication that a security team must document to justify remediation efforts.Why the Other Options Are Wrong
'Product software compatibility' (B) is a functional issue, not primarily a security one. 'Ease of recovery' (C) relates to disaster recovery planning rather than the inherent risk of the OS state. 'Cost of replacement' (D) is a financial or administrative consideration; while important for budgeting, it is not a security implication in the context of vulnerability management.Community Comment Notes
Community comments consistently highlight that EOL means no more security updates. One comment notes that determining replacement costs is outside the cybersecurity team's primary responsibility, reinforcing why D is incorrect. Another emphasizes that the question asks for documentation of the security implication, not a solution or business metric.Exam Strategy
When asked for a 'security implication,' always filter out non-security factors like cost, convenience, or general functionality. Focus on risks related to confidentiality, integrity, and availability, such as unpatched vulnerabilities, weak encryption, or lack of access controls.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →