What Is the Most Critical Risk of Running End-of-Life Software?
A third-party vendor is moving a particular application to the end-of-life stage at the end of the current year. Which of the following is the most critical risk if the company chooses to continue running the application?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between operational inconveniences and security-critical risks; the key trap is confusing 'lack of support' with 'lack of security updates', the latter being the direct cause of exploitable vulnerabilities.
When a third-party vendor ends support for an application, the most critical risk is the lack of security updates, leaving known vulnerabilities unpatched and the organization exposed to exploitation. Community consensus strongly favors option A.
Choosing 'Lack of support' is a common mistake because support covers multiple areas, but the highest-impact consequence of end-of-life is the cessation of security patches, which directly increases cyber risk.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
End-of-life (EOL) means the vendor no longer provides patches, including security fixes. Without security updates, known vulnerabilities remain open, making the application an easy target for attackers. This is the most critical risk because it directly exposes the company to data breaches, malware, and compliance violations.
Why the Other Options Are Wrong
'Lack of new features' is a functional limitation, not a security risk. 'Lack of support' is broader but secondary—support alone does not mitigate vulnerabilities if no patches are issued. 'Lack of source code access' may hinder internal fixes, but it is not the primary risk in a typical third-party EOL scenario.
Community Comment Notes
The comments unanimously endorse option A, with one simply stating "A. Lack of security updates is correct." Another comment notes "A | A GPT," indicating agreement. These reinforce the exam's focus on security implications rather than general maintenance concerns.
Official Reference
Exam Strategy
When asked for the 'most critical risk' of end-of-life software, immediately think about security patches and vulnerabilities. Eliminate options that describe non-security impacts, and remember that 'support' is a means to an end, not the end itself.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →