How Should You Treat Risk When a Critical System Loses Vendor Support?

A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and must stay online. Which of the following risk treatments is the most appropriate in this situation?

  1. Reject
  2. Accept Source Reference Answer
  3. Transfer
  4. Avoid

Community Votes

B
70%
C
30%

70% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to apply formal risk treatment frameworks under strict operational constraints, with the common trap being the temptation to transfer risk via insurance rather than acknowledging the necessity of acceptance with mitigations.

This question explores risk treatment strategies when a legacy system remains operational despite losing vendor support. The community consensus strongly favors accepting the risk while deploying compensating security controls, as the system's critical nature precludes replacement or modification.

Many candidates incorrectly select Transfer, believing that purchasing cyber insurance is the best way to handle unsupported critical systems. However, insurance only addresses financial impact after an incident occurs and does not satisfy the operational requirement of maintaining a vulnerable system without viable alternatives.

Community Discussion (6 comments)

ProudFather 👍 6 Selected: B
In this scenario, the organization has no choice but to accept the risk associated with the unsupported system. The system is critical to the business, and it cannot be modified or replaced without disrupting operations. Therefore, the organization must implement additional security measures, such as regular vulnerability assessments and patching, to mitigate the risk as much as possible.
fd4ea1a 👍 5 Selected: C
If transfer wasnt here I would go with accept, but transfer is getting insurance for something that you know will happen. then best solution would get the insurance, for something that you know will cause an issue.
MarysSon 👍 1 Selected: C
The best answer is C - Transfer, an organization can purchase insurance to cove the cost of data loss or business interruption. No company can Accept a rick that is critical to it's operations.
Fagann 👍 2 Selected: B
Briefly the company just accepted risk and there is no other way.
Fourgehan 👍 2 Selected: B
In this scenario, the system is critical to the business, cannot be modified, and must stay online, but it is no longer receiving support from the vendor. The most appropriate risk treatment is to accept the risk, because the system's continued operation is essential to the business, and there is no practical way to eliminate or replace it. Accepting the risk means acknowledging the vulnerabilities or potential issues but deciding that the benefits of keeping the system running outweigh the risks. The organization may need to implement additional measures, such as enhanced monitoring, custom security controls, or risk mitigation strategies, to manage the risks associated with the unsupported system
Chris__ 👍 4 Selected: B
In this scenario, the system is critical to the business, cannot be modified, and must stay online despite no longer receiving vendor support. Since replacing or updating the system is not an option, the most appropriate risk treatment is to accept the risk while implementing additional mitigating controls to reduce potential vulnerabilities.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Risk Treatment Frameworks

In CompTIA Security+ risk management scenarios, organizations typically choose between four primary treatments: Avoid, Transfer, Mitigate, and Accept. Each option carries distinct operational and financial implications. The scenario explicitly states the system is critical, cannot be modified, and must remain online. These hard constraints immediately eliminate Avoid, which would require decommissioning the system or altering business processes, and rule out standard Mitigation through patching or configuration changes since the environment cannot be modified.

Why Acceptance is the Correct Choice

The correct answer is Accept. According to industry standards like NIST SP 800-39, risk acceptance is appropriate when the cost of implementation exceeds the potential loss, or when operational necessities force continued usage of a vulnerable asset. As noted by top-voted community contributors, the organization has no practical alternative but to acknowledge the inherent risks of running an unsupported system ([1], [5]). Acceptance does not mean ignoring the threat; it requires formal documentation and the deployment of compensating controls such as network segmentation, enhanced monitoring, regular vulnerability assessments, and strict access restrictions to minimize exposure until the system can be replaced.

Why Other Options Fail

Transfer (Option C) is the most frequent distractor. While purchasing cyber insurance shifts financial liability, it does not reduce technical risk, nor does it comply with security baselines that mandate supported software. Insurers frequently exclude claims related to known vulnerabilities in end-of-life systems, making this a financially risky strategy ([2], [3]). Reject (Option A) is not a recognized risk treatment category within standard cybersecurity frameworks. Ultimately, when operational continuity overrides technical remediation, formal acceptance paired with defensive layering is the only compliant and pragmatic path forward.

Official Reference

Exam Strategy

When faced with risk management questions, always map the scenario's hard constraints (e.g., "must stay online," "cannot be modified") directly to the available treatments first. If avoidance and mitigation are operationally impossible, acceptance becomes the default choice, provided you mentally note that compensating controls will still be required.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide