Which Technique Best Secures a Critical End-of-Life System?
A systems administrator notices that one of the systems critical for processing customer transactions is running an end-of-life operating system. Which of the following techniques would increase enterprise security?
Community Votes
61% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the application of compensating controls versus risk elimination, with the common trap being the selection of decommissioning due to its theoretical perfect security despite violating operational requirements.
This question evaluates how to apply compensating controls for an unsupported operating system without disrupting business operations. The community consensus strongly supports network isolation via a dedicated VLAN as the optimal balance between security enhancement and transaction continuity.
Candidates frequently choose decommissioning (C) because it completely removes the vulnerability of an unpatched EOL system. However, they overlook the explicit scenario constraint that the server is critical for processing customer transactions, making immediate removal an unacceptable business risk.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Compensating Controls for Legacy Systems
When an organization runs an end-of-life (EOL) operating system, it faces inherent vulnerabilities due to the cessation of vendor security patches. The primary objective in such scenarios is to apply compensating controls that reduce the attack surface until the system can be securely replaced.Why Network Isolation (Option B) is Correct
Placing the system in an isolated VLAN effectively implements network segmentation, which is a foundational compensating control. By restricting inbound and outbound traffic to only necessary services and blocking lateral movement, the organization significantly reduces the risk of exploitation while maintaining business continuity. As noted by the community, this approach balances security needs with operational demands [1][2][5].Why the Other Options Are Incorrect
- Installing HIDS (Option A): While Host-based Intrusion Detection Systems monitor for suspicious activity, they are detective rather than preventive tools. They cannot stop an exploit targeting an unpatched kernel or application flaw.
- Decommissioning the system (Option C): Though theoretically the safest option, decommissioning eliminates business functionality. In SY0-701, questions involving critical infrastructure require solutions that preserve availability unless a maintenance window or phased replacement is specified.
- Encrypting the hard drive (Option D): Full disk encryption protects data at rest from physical theft but does nothing to mitigate network-based attacks or exploitation of outdated software components.
Strategic Approach
Always map the scenario to the risk treatment options: Avoid, Transfer, Mitigate, or Accept. When elimination causes unacceptable downtime, mitigation through architectural controls like VLANs, firewalls, or air-gapping becomes the correct exam answer.Official Reference
Exam Strategy
Always scan the question for operational constraints like critical, production, or customer-facing. These keywords immediately disqualify high-impact solutions like decommissioning or forced reboots, steering you toward compensating controls that prioritize both security and availability.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →