CISSP - Asset Security (10% of the exam) - Section 2.5

Ensure appropriate asset retention covering end-of-life (EOL) and end-of-support (EOS).

Define retention policies that govern how long assets are kept in relation to legal, regulatory, and business requirements, including legal hold obligations that override standard schedules. Recognise the security and compliance risks created by retaining end-of-life (EOL) or end-of-support (EOS) assets beyond their supported lifespan.

retention policyend-of-lifeend-of-supportlegal hold

Practice question for this objective

Free sampleAsset Securityeasy

During an asset inventory review, a security analyst discovers that several pharmacy point-of-sale terminals are running an operating system version that reached end-of-life two years ago. The vendor no longer issues patches. Which action should the security manager recommend FIRST?

  • AEscalate the finding to the business owner with a risk assessment so that an informed decision can be made about replacement, compensating controls, or formal acceptance. Correct
  • BReimage the terminals with a community-supported fork of the same operating system so that patches continue to flow from independent maintainers.
  • CRemove the terminals from the network at the next maintenance window to eliminate the unpatched exposure on the production segment.
  • DDocument the gap in the next quarterly asset report and continue routine vulnerability scanning until the issue is naturally addressed.
When an asset has passed end-of-life, the security manager's first step is escalation to the business owner with a risk assessment, not unilateral technical action. Assets past end-of-life no longer receive vendor patches, so vulnerabilities accumulate without remediation. CISSP positions security as an advisor to the business: the manager translates the technical reality into a risk decision the owner can take, choosing between replacement, compensating controls such as network isolation, or documented risk acceptance. Acting unilaterally, whether by removing the system or applying an unsupported fork, bypasses that governance step.

Why A is correct: The CISSP-favoured move is to surface the risk to the owner with enough evidence to choose between remediation, mitigation, and acceptance; the security manager facilitates the risk decision rather than acting unilaterally.

Why B is wrong: Community forks may introduce unsupported components into a regulated environment and rarely satisfy compliance auditors looking for a vendor-supported baseline; this is a technical workaround that bypasses the risk decision that needs to be made first.

Why C is wrong: Disconnecting pharmacy terminals affects patient care and revenue, and the decision belongs to the business owner once they understand the risk; the security manager does not own that trade-off and should not pre-empt it.

Why D is wrong: Logging the finding without escalation leaves an unpatched, end-of-life system in production indefinitely; passive monitoring is not a treatment, and routine reporting is not the same as a formal risk decision.

See more CISSP practice questions, answers explained.

Exam traps in Asset Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Proceed with the scheduled destruction because the retention policy was approved by the board and predates the litigation hold notice from counsel.

    Why it is wrong: Retention schedules govern routine disposal, but a litigation hold legally suspends that schedule for in-scope records; destroying them on schedule risks spoliation sanctions and undermines the very purpose of the hold.

  • Allow the standard ninety-day rolling deletion to continue so that retention practice remains consistent across all warehouse sites in the estate.

    Why it is wrong: Treating an active incident the same as routine retention risks losing evidence that may be needed for an HR case or future litigation; consistency is valuable for unrelated footage, not for material under active review.

  • Terminate the vendor contract and bring the archive in-house to remove third-party handling risk entirely

    Why it is wrong: Termination is disproportionate before assessing whether the vendor's controls are adequate, and in-house archives carry their own handling risks. CISSP favours risk-based action over reflexive removal of a third party that may already meet requirements.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.