CAS-001 · Question #195
Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain buffer overflow…
The correct answer is D. Distributed patch management system where all updates are tested in a lab environment prior to. The scenario describes a failed patch that crashed critical servers - the lesson is that updates must be validated before reaching production. A distributed patch management system with lab testing prior to deployment satisfies both requirements: testing in a lab environment…
Question
Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain buffer overflow attacks. The security administrator is required to ensure all systems have the latest updates while minimizing any downtime. Which of the following is the BEST risk mitigation strategy to use to ensure a system is properly updated and operational?
Options
- ADistributed patch management system where all systems in production are patched as updates
- BCentral patch management system where all systems in production are patched by automatic
- CCentral patch management system where all updates are tested in a lab environment after being
- DDistributed patch management system where all updates are tested in a lab environment prior to
How the community answered
(31 responses)- A3% (1)
- B16% (5)
- C6% (2)
- D74% (23)
Explanation
The scenario describes a failed patch that crashed critical servers - the lesson is that updates must be validated before reaching production. A distributed patch management system with lab testing prior to deployment satisfies both requirements: testing in a lab environment catches defective updates before they can cause downtime, and the distributed model allows phased rollouts that reduce the blast radius if an issue is missed. Option A patches production systems without testing. Option B uses central automatic patching with no testing, which mirrors what caused the original failure. Option C tests in the lab 'after' updates are applied to production, which is backwards and would not prevent downtime. Only Option D (test first, then deploy) minimizes downtime while ensuring updates reach all systems.
Topics
Community Discussion
No community discussion yet for this question.