How Should You Treat Risk When a Critical System Loses Vendor Support?
A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and must stay online. Which of the following risk treatments is the most appropriate in this situation?
Community Votes
70% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to apply formal risk treatment frameworks under strict operational constraints, with the common trap being the temptation to transfer risk via insurance rather than acknowledging the necessity of acceptance with mitigations.
This question explores risk treatment strategies when a legacy system remains operational despite losing vendor support. The community consensus strongly favors accepting the risk while deploying compensating security controls, as the system's critical nature precludes replacement or modification.
Many candidates incorrectly select Transfer, believing that purchasing cyber insurance is the best way to handle unsupported critical systems. However, insurance only addresses financial impact after an incident occurs and does not satisfy the operational requirement of maintaining a vulnerable system without viable alternatives.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Risk Treatment Frameworks
In CompTIA Security+ risk management scenarios, organizations typically choose between four primary treatments: Avoid, Transfer, Mitigate, and Accept. Each option carries distinct operational and financial implications. The scenario explicitly states the system is critical, cannot be modified, and must remain online. These hard constraints immediately eliminate Avoid, which would require decommissioning the system or altering business processes, and rule out standard Mitigation through patching or configuration changes since the environment cannot be modified.
Why Acceptance is the Correct Choice
The correct answer is Accept. According to industry standards like NIST SP 800-39, risk acceptance is appropriate when the cost of implementation exceeds the potential loss, or when operational necessities force continued usage of a vulnerable asset. As noted by top-voted community contributors, the organization has no practical alternative but to acknowledge the inherent risks of running an unsupported system ([1], [5]). Acceptance does not mean ignoring the threat; it requires formal documentation and the deployment of compensating controls such as network segmentation, enhanced monitoring, regular vulnerability assessments, and strict access restrictions to minimize exposure until the system can be replaced.
Why Other Options Fail
Transfer (Option C) is the most frequent distractor. While purchasing cyber insurance shifts financial liability, it does not reduce technical risk, nor does it comply with security baselines that mandate supported software. Insurers frequently exclude claims related to known vulnerabilities in end-of-life systems, making this a financially risky strategy ([2], [3]). Reject (Option A) is not a recognized risk treatment category within standard cybersecurity frameworks. Ultimately, when operational continuity overrides technical remediation, formal acceptance paired with defensive layering is the only compliant and pragmatic path forward.
Official Reference
Exam Strategy
When faced with risk management questions, always map the scenario's hard constraints (e.g., "must stay online," "cannot be modified") directly to the available treatments first. If avoidance and mitigation are operationally impossible, acceptance becomes the default choice, provided you mentally note that compensating controls will still be required.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →