Study. uk . com
  1. Home
  2. All questions
  3. Question 109

CompTIA Security+ study material · question 109 of 611

A critical flaw is found in an application whose vendor ended support two years ago. Why is this different from a normal unpatched finding?

  1. The vendor remains contractually liable for a fix
  2. End-of-life software is excluded from vulnerability management
  3. The CVSS score cannot be calculated
  4. No patch will ever be released, so it is a permanent rather than a delayed finding
Show the answer

Answer: D. No patch will ever be released, so it is a permanent rather than a delayed finding

Unsupported software will not be fixed, so the response must be compensating controls, isolation or replacement.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.1 Risk Responses

Challenge yourself on this topic → Study as cards