CompTIA Security+ (SY0-701)Security OperationsMedium
During an asset inventory review, a security analyst discovers several production servers running an operating system version the vendor no longer supports. Which risk should the analyst prioritize addressing?
- AThe vendor will no longer release security patches for newly discovered vulnerabilities
- BThe servers will experience slower boot times compared to newer OS versions
- CThe organization will incur higher annual licensing renewal fees
- DPeripheral hardware may lose compatibility with the operating system drivers
Show answer & explanationAnswer & explanation
Correct answer: A. The vendor will no longer release security patches for newly discovered vulnerabilities
When an OS reaches end-of-life (EOL)/end-of-support (EOS), the vendor stops issuing security patches, leaving systems permanently exposed to newly discovered vulnerabilities with no remediation path other than migration or compensating controls.
Why the other options are wrong
- B. Boot performance is a minor operational issue, not a security priority.
- C. Licensing cost changes are a business/financial concern, not the primary security risk.
- D. Hardware compatibility is a functional concern secondary to the lack of security patching.
End-of-Life (EOL) / End-of-Support (EOS) Software
Software or hardware that a vendor no longer maintains or patches, creating unmitigated security exposure over time.
- No further security patches after EOS date
- Common target for exploit development
- Should be tracked in asset management/CMDB
- Mitigations include upgrading, isolation, or compensating controls
Memory trick: When support Ends, patches Leave — that's EOL's real risk