nerdexam
Oracle

1Z0-116 · Question #27

You check the Risk Matrix of the latest Critical Patch Update (CPU). One of the " Common Vulnerability and Exposure'' reports (CVEs) has Base Score that is above 9 in the Risk Matrix. Which one is…

The correct answer is A. Request a one off patch exception from Oracle Support. Option A is correct because Oracle does not offer one-off patch exceptions as a supported remediation method for CVEs - customers must apply fixes through Oracle's standard patching channels, regardless of severity. Options C (Upgrade to a new Release), D (Install a Release…

Introduction to Database Security

Question

You check the Risk Matrix of the latest Critical Patch Update (CPU). One of the " Common Vulnerability and Exposure'' reports (CVEs) has Base Score that is above 9 in the Risk Matrix. Which one is not a supported method to address this CVE?

Options

  • ARequest a one off patch exception from Oracle Support.
  • BImplement a workaround recommended by Oracle Support.
  • CUpgrade to a new Release.
  • DInstall a new Release Update.
  • EInstall a new Release Update Revision.

How the community answered

(50 responses)
  • A
    92% (46)
  • B
    2% (1)
  • D
    2% (1)
  • E
    4% (2)

Explanation

Option A is correct because Oracle does not offer one-off patch exceptions as a supported remediation method for CVEs - customers must apply fixes through Oracle's standard patching channels, regardless of severity. Options C (Upgrade to a new Release), D (Install a Release Update), and E (Install a Release Update Revision) are all valid supported methods because they deliver the actual security fix through Oracle's official release lifecycle. Option B is also valid because Oracle Support may publish documented workarounds (such as configuration changes or access controls) as an interim measure while a patch is being applied. The key distinction is that Oracle's patch policy is standardized and non-negotiable - there is no "exception" process for receiving a bespoke fix outside of the normal CPU/RU/RUR delivery model.

Memory tip: Think of it as "Oracle gives you a menu, not a custom order" - you can upgrade, patch, revise, or workaround, but you cannot request a special one-off fix just for your environment.

Topics

#Patch Management#CVE Vulnerability#Risk Assessment#Security Policy

Community Discussion

No community discussion yet for this question.

Full 1Z0-116 Practice