CompTIA CASP+ Practice Test 2025 - Free CASP+ Practice Questions and Study Guide

Question: 1 / 565

If an organization has legacy applications that cannot comply with a password length policy, what should be done?

Remove the legacy applications from the network

Implement multi-factor authentication on these applications

Provide a business justification for a risk exception

In situations where an organization faces challenges with legacy applications that cannot meet modern security policies, providing a business justification for a risk exception is a practical approach. This option allows the organization to acknowledge the limitations of the legacy systems while simultaneously assessing and documenting the associated risks.

This process involves evaluating the potential vulnerabilities posed by the inability of these applications to comply with the password length policy, followed by outlining the rationale for accepting those risks based on business needs, operational impact, or resource constraints. By formalizing the exception, the organization can maintain compliance with regulatory and internal standards while developing a plan for future upgrades or integrations that better align with security best practices.

This path also encourages the organization to prioritize legacy systems for review or improvement in the future, driving the intent to eventually mitigate identified risks through better technology without disrupting business operations immediately.

Get further explanation with Examzify DeepDiveBeta

Upgrade all applications immediately

Next Question

Report this question

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy