SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A vulnerability scan reports that a public web server is running an operating system version that no longer receives security updates. Which issue is present?
⚠ Common exam trap
Watch out — candidates often confuse 'outdated component' with 'weak permissions' because both involve configuration issues, but the question specifically describes a version that no longer receives updates, which is a lifecycle/obsolescence problem, not a permissions misconfiguration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Outdated component
An operating system version that no longer receives security updates is an outdated component. This means the vendor has ceased patching known vulnerabilities, leaving the system exposed to exploits that target unpatched flaws. In the context of a public web server, this directly violates the principle of maintaining a secure baseline and is a common finding in vulnerability scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Weak permissions
Why it's wrong here
Weak permissions refer to misconfigured file or resource access controls, such as overly broad ACLs or world-writable directories. A vulnerability scan flagging an unsupported operating system is specifically tied to the software support lifecycle, not access rights. Even a server with strict file permissions can run an OS that no longer receives security patches, so weak permissions do not account for this finding.
- ✓
Outdated component
Why this is correct
An unsupported operating system is an outdated component because the vendor has ceased releasing security updates and patches for it. This leaves known vulnerabilities permanently unmitigated, making the server more exposed to exploitation. In vulnerability scan reports, an end-of-life OS is typically categorized under outdated components, reflecting the software's obsolete state. This is the correct classification because the root cause is the lack of vendor support, not an access or network issue.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning is an attack that corrupts the domain name resolution process, for example by altering DNS records or cache entries, redirecting users to malicious addresses. This is a network-layer integrity issue that has no connection to the installed operating system version or its patch status. A vulnerability scan reporting an unsupported OS is unrelated to DNS infrastructure, so this option does not match the finding.
- ✗
Smishing
Why it's wrong here
Smishing is a social engineering technique delivered via SMS text messages, tricking recipients into revealing credentials or installing malware through deceptive links. This vector targets end users' mobile devices, not the server's software configuration or patch level. A vulnerability scan of a public web server would never classify an unsupported OS as smishing, since the two concerns are entirely distinct security domains.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning and Assessment
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.