Legacy Application Risks

The Impact of Using an Unsupported Operating System for a Legacy Application

Prev Question Next Question

Question

A legacy application is running on an operating system that is no longer supported by the vendor.

If the organization continues to use the current application, which of the following should be the IS auditor's GREATEST concern?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

The correct answer is A. Potential exploitation of zero-day vulnerabilities in the system.

Explanation:

A legacy application is an old software application that is no longer updated or supported by the vendor. If the organization continues to use a legacy application on an unsupported operating system, it exposes the organization to a number of risks. One of the major risks is the potential exploitation of zero-day vulnerabilities in the system.

A zero-day vulnerability is a software vulnerability that is unknown to the software vendor and can be exploited by attackers before the vendor releases a patch. In the case of an unsupported operating system, there will be no patches or updates released by the vendor to address the zero-day vulnerability.

If an attacker exploits a zero-day vulnerability in the legacy application, they can gain unauthorized access to the system and steal sensitive information, modify or delete data, and cause system downtime. This can have serious consequences for the organization, including financial loss, damage to reputation, and legal liability.

Option B. Inability to update the legacy application database is also a concern, but it is not the greatest concern. It is possible to maintain the legacy application database without updating the operating system.

Option C. Increased cost of maintaining the system is also a concern, but it is not the greatest concern. The cost of maintaining the system may increase due to the need for specialized skills or the use of custom patches and workarounds to address the lack of vendor support.

Option D. Inability to use the operating system due to potential license issues is not relevant to the question. The question assumes that the organization is using the unsupported operating system to run the legacy application.