yes you can
1/ install windows 7 sp1
2/ download and apply
never10
3/ update windows to the latest version, if you want
4/ use something with anti-exploit or antiexploit-like feature: kaspersky, eset, hitmanpro.alert, 0patch, malwarebytes anti-exploit, NVT OSArmor, comodo firewall, voodooshield
5/ use syshardener and apply some custom settings
6/ block all inbound connections using your firewall and only allow something you really need or trust
7/ use your firewall to block outbound connections of vulnerable proccesses, you can have a look at syshardener's firewall blocklist as a great example
not sure if 0patch can be helpful to patch vulnerabilities in windows but it worth looking if you don't use windows 10
windows 7 is still one of the best windows versions for very low-end PCs so IMO, it won't die anytime soon
people with low-end machines usually care more about performance than vulnerability