Which Technique Best Secures a Critical End-of-Life System?

A systems administrator notices that one of the systems critical for processing customer transactions is running an end-of-life operating system. Which of the following techniques would increase enterprise security?

  1. Installing HIDS on the system
  2. Placing the system in an isolated VLAN Source Reference Answer
  3. Decommissioning the system
  4. Encrypting the system's hard drive

Community Votes

B
61%
C
39%

61% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the application of compensating controls versus risk elimination, with the common trap being the selection of decommissioning due to its theoretical perfect security despite violating operational requirements.

This question evaluates how to apply compensating controls for an unsupported operating system without disrupting business operations. The community consensus strongly supports network isolation via a dedicated VLAN as the optimal balance between security enhancement and transaction continuity.

Candidates frequently choose decommissioning (C) because it completely removes the vulnerability of an unpatched EOL system. However, they overlook the explicit scenario constraint that the server is critical for processing customer transactions, making immediate removal an unacceptable business risk.

Community Discussion (8 comments)

a4e15bd 👍 13
B. Placing the system in an isolated VLAN Give that the system is critical for processing customer transactions, decommissioning immediately might impact business continuity. The next best approach is to place the system in an isolated VLAN.
Migzz 👍 8
Why would you "Decommission the system" when it is critical for transitions? The answer is B, Isolate it until you're ready to make the relevant changes or ready to replace it.
ProudFather 👍 2 Selected: C
C. Decommissioning the system The most secure option is to decommission the system entirely. End-of-life systems are no longer supported by the vendor, meaning they will not receive security patches. This makes them highly vulnerable to attacks. By decommissioning the system, the organization can eliminate the risk associated with it. While the other options may provide some level of security, they do not address the fundamental issue of the system being end-of-life.
nyyankee718 👍 3 Selected: C
Yes it is critical so it should be replaced soon, VLAN can be short term
nillie 👍 2 Selected: B
The best technique to increase enterprise security in this situation is: B. Placing the system in an isolated VLAN By placing the system in an isolated VLAN, the organization can reduce the risk of the outdated system being exploited by limiting its network exposure and controlling access to and from the critical system. This helps to minimize the impact that vulnerabilities in the end-of-life operating system could have on the broader network.
Glacier88 👍 1 Selected: B
Placing the system in an isolated VLAN: This will physically separate the critical system from the rest of the network, reducing the risk of unauthorized access or attacks. Installing HIDS on the system: While an HIDS can detect and alert on suspicious activity, it might not be enough to mitigate the risks associated with an end-of-life operating system, which lacks security updates and patches. Decommissioning the system: This is a potential solution if the system can be replaced with a more secure alternative. However, if the system is critical for business operations, decommissioning it might not be feasible. Encrypting the system's hard drive: Encryption can protect the data stored on the system, but it doesn't address the security vulnerabilities associated with an end-of-life operating system.
Dharmesh16 👍 8 Selected: B
techniques would increase "enterprise" security. you can use system but system can't connect with other devices on network
qacollin 👍 2 Selected: C
Yes, decommissioning the system is generally the most effective approach for addressing the security risks associated with running an end-of-life operating system. GPT

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Compensating Controls for Legacy Systems

When an organization runs an end-of-life (EOL) operating system, it faces inherent vulnerabilities due to the cessation of vendor security patches. The primary objective in such scenarios is to apply compensating controls that reduce the attack surface until the system can be securely replaced.

Why Network Isolation (Option B) is Correct

Placing the system in an isolated VLAN effectively implements network segmentation, which is a foundational compensating control. By restricting inbound and outbound traffic to only necessary services and blocking lateral movement, the organization significantly reduces the risk of exploitation while maintaining business continuity. As noted by the community, this approach balances security needs with operational demands [1][2][5].

Why the Other Options Are Incorrect

  • Installing HIDS (Option A): While Host-based Intrusion Detection Systems monitor for suspicious activity, they are detective rather than preventive tools. They cannot stop an exploit targeting an unpatched kernel or application flaw.
  • Decommissioning the system (Option C): Though theoretically the safest option, decommissioning eliminates business functionality. In SY0-701, questions involving critical infrastructure require solutions that preserve availability unless a maintenance window or phased replacement is specified.
  • Encrypting the hard drive (Option D): Full disk encryption protects data at rest from physical theft but does nothing to mitigate network-based attacks or exploitation of outdated software components.

Strategic Approach

Always map the scenario to the risk treatment options: Avoid, Transfer, Mitigate, or Accept. When elimination causes unacceptable downtime, mitigation through architectural controls like VLANs, firewalls, or air-gapping becomes the correct exam answer.

Official Reference

Exam Strategy

Always scan the question for operational constraints like critical, production, or customer-facing. These keywords immediately disqualify high-impact solutions like decommissioning or forced reboots, steering you toward compensating controls that prioritize both security and availability.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide