exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 89 discussion

Actual exam question from CompTIA's SY0-601
Question #: 89
Topic #: 1
[All SY0-601 Questions]

Which of the following risk management strategies would an organization use to maintain a legacy system with known risks for operational purposes?

  • A. Acceptance
  • B. Transference
  • C. Avoidance
  • D. Mitigation
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
stoneface
Highly Voted 2 years, 8 months ago
Selected Answer: A
Accepting risk, or risk acceptance, occurs when a business or individual acknowledges that the potential loss from a risk is not great enough to warrant spending money to avoid it.
upvoted 76 times
Gino_Slim
2 years, 6 months ago
In stoneface we trust
upvoted 38 times
...
Old_Boy_
1 year, 6 months ago
I will right your name on my cv
upvoted 11 times
...
alittlesmarternow
1 year, 4 months ago
Acceptance is something you do. You accept the risk, but mitigation is something you use. You use known mitigation tactics for "KNOWN RISK". people are drinking your cool-aid but I believe you are wrong on this one.
upvoted 3 times
klinkklonk
1 year, 3 months ago
Mitigation is the answer. Legacy systems with known vulnerabilities can be mitigated with things such as network segmentation. No company would just accept the risk when mitigation is possible. Stoneface has some useful answers, but I've seen them give 5 or more wrong answers in the first 100 questions.
upvoted 3 times
...
...
...
Confuzed
Highly Voted 2 years ago
Selected Answer: D
Per the CompTIA official study guide: "By definition, legacy platforms are unpatchable. Such systems are highly likely to be vulnerable to exploits and must be protected by security controls other than patching, such as isolating them to networks that an attacker cannot physically connect to." "Risk acceptance (or tolerance) means that no countermeasures are put in place either because the level of risk does not justify the cost or because there will be unavoidable delay before the countermeasures are deployed." So Risk acceptance would be counter to what CompTIA says MUST be done with legacy systems. "Risk mitigation (or remediation) is the overall process of reducing exposure to or the effects of risk factors. If you deploy a countermeasure that reduces exposure to a threat or vulnerability that is risk deterrence (or reduction). Risk reduction refers to controls that can either make a risk incident less likely or less costly (or perhaps both)." That is what CompTIA says MUST be done on a legacy system... reduce risk. So the answer is risk mitigation.
upvoted 25 times
...
Salsa12
Most Recent 11 months, 3 weeks ago
Selected Answer: A
While Mitigation (D) is indeed a common risk management strategy, the specific scenario mentioned is about maintaining a legacy system with known risks for operational purposes. Here's a more detailed comparison to clarify why Acceptance (A) is the more appropriate answer: Acceptance (A) Definition: Acknowledging the risk and deciding to continue operations without any immediate changes because the benefits outweigh the risks, or other risk management strategies are not feasible or cost-effective. Context: The question specifies maintaining a legacy system with known risks. This implies the organization is aware of the risks but chooses to continue using the system due to operational necessity, cost constraints, or other reasons. This aligns well with the concept of risk acceptance.
upvoted 1 times
...
RyanL26
1 year ago
Selected Answer: A
At this point, the org will be accepting that the Legacy machine is no longer supported, and that things will go wrong.
upvoted 1 times
...
MortG7
1 year, 2 months ago
Key word is legacy..in other words, end of life or vendor support is no longer available. Mitigation SOUNDS good, but in this context, it is wrong. "ACCEPTANCE" is correct..
upvoted 3 times
...
Drosk5
1 year, 2 months ago
Selected Answer: A
Remember this " to maintain a legacy system"
upvoted 3 times
realkrome
1 year ago
Yeah, accepting the risk isn't maintaining anything. To maintain is to provide upkeep, and if it's a legacy system (EOS/EOL) the upkeep must be done through your own means ie, strict access control, airgapping, explicit policies etc.
upvoted 2 times
Mehe323
1 year ago
Exactly, you need compensating controls and therefor the answer is D. mitigation.
upvoted 1 times
...
...
...
DrakeMallard
1 year, 2 months ago
Selected Answer: D
After going over the question multiple times I am going with Mitigation. The question says which risk management strategy would an organization use to MAINTAIN a legacy system wirh known risk. You can accept the problem all day but what are you going to do to fix the problem or if it can't be fixed, find a workaround Acceptance means that the organization acknowledges the risks associated with the legacy system but chooses to tolerate them rather than invest resources in changing or replacing the system. Mitigation involves taking actions to reduce the impact or likelihood of risks. In the context of a legacy system, this could involve implementing additional security measures implementing workarounds like segmenting the network to address specific ulnerabilities.
upvoted 2 times
...
johnabayot
1 year, 3 months ago
Selected Answer: D
Mitigation works well with Legacy systems with known vulnerability that lacks vendor support.
upvoted 2 times
...
Yomzie
1 year, 3 months ago
"...risk management strategies would an organization use to maintain a legacy system" Legacy systems, by definition, means old, likely-non-patchable computers. So, rather than accept the likelihood of them remaining on the corporate network and being susceptible to attacks, one can mitigate such scenario by (1.) reducing/eliminating shared access to them; (2.) removing them from being able to browse the internet; (3.) ensuring only specific users have access to them for specified use-case scenarios. I think, mitigation (option D) is the best option in this case.
upvoted 1 times
...
jade290
1 year, 3 months ago
Selected Answer: A
It is definitely acceptance. A real world example is applications written in AngularJS. The very next release of Angular would have required a complete and total rewrite. Many Program Managers decided not to take on the cost of completely rewriting a new application so they accepted the risk and did not spend additional resources to upgrade.
upvoted 1 times
...
klinkklonk
1 year, 3 months ago
Selected Answer: D
Mitigation. There are ways to mitigate vulnerabilities on legacy systems. No company would just accept the risk and do nothing when they have the option to mitigate.
upvoted 1 times
...
ganymede
1 year, 5 months ago
Selected Answer: D
D. Mitigation It's common for organizations to use Legacy systems in their environments. Oftentimes they do not have a choice. Just because they are using Legacy systems does not mean they cannot take any steps to reduce the risk those Legacy systems expose them to. The answer is mitigation because there are still actions they can take to reduce the risk. For example Network segmentation.
upvoted 3 times
...
TheFivePips
1 year, 6 months ago
I hate these types of questions. Here's what ChatGPT has to say after some pushback: While mitigation is a valid risk management strategy and is often preferred when it's possible to reduce or eliminate risks, it might not be the best choice in the context of maintaining a legacy system with known risks for operational purposes. Here's why: Legacy systems can be expensive and resource-intensive to modify or enhance. Mitigation efforts may require significant investments in terms of time, money, and effort, and these resources might be better spent on more critical projects or system upgrades. Modifying a legacy system to mitigate risks can introduce new vulnerabilities or issues, especially if the system is complex and poorly documented. It's important to tread carefully to avoid inadvertently creating more problems. Making changes to a legacy system can disrupt normal operations and introduce downtime or service interruptions, which might not be acceptable in cases where the legacy system is critical for ongoing operations. In some cases, the legacy system may be so outdated that viable mitigation options are limited or impractical.
upvoted 1 times
...
Ruger
1 year, 6 months ago
A. Acceptance When an organization chooses to maintain a legacy system with known risks for operational purposes, it is essentially accepting the risks associated with that system. This is a risk management strategy known as risk acceptance. In this case, the organization acknowledges the existence of risks but continues to use the system due to various reasons, such as cost-effectiveness, business continuity, or other operational considerations.
upvoted 1 times
...
PropheticBettor
1 year, 6 months ago
Mitigation is accepting the risk while trying to minimize it as you can. Acceptance is simply letting it be. That wouldn't be smart since we still have to use the equipment in daily operations. Must accept while doing our best to mitigate risk
upvoted 1 times
...
J0EL
1 year, 7 months ago
Selected Answer: D
D. Mitigation. The organization would use the risk management strategy of mitigation to maintain a legacy system with known risks for operational purposes. Mitigation strategies are used to reduce the potential impact of risks or likelihood of occurrence. For a legacy system, mitigation measures may include regular maintenance and patching, limiting who has access to the system, and monitoring the system for any signs of compromise. Acceptance involves acknowledging the risks associated with the system but choosing to use it anyway without taking any additional action to reduce the risk. Transference involves transferring the risk to a third party through insurance or outsourcing, while avoidance involves avoiding the use of the system altogether.
upvoted 3 times
...
TreeeSon
1 year, 7 months ago
Selected Answer: A
I will go with A seeing as how legacy systems have more limitations/ vulnerabilities that cannot be completely eliminated
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago