nerdexam
CompTIA

CAS-001 · Question #195

Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain buffer overflow…

The correct answer is D. Distributed patch management system where all updates are tested in a lab environment prior to. The scenario describes a failed patch that crashed critical servers - the lesson is that updates must be validated before reaching production. A distributed patch management system with lab testing prior to deployment satisfies both requirements: testing in a lab environment…

Enterprise Security

Question

Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain buffer overflow attacks. The security administrator is required to ensure all systems have the latest updates while minimizing any downtime. Which of the following is the BEST risk mitigation strategy to use to ensure a system is properly updated and operational?

Options

  • ADistributed patch management system where all systems in production are patched as updates
  • BCentral patch management system where all systems in production are patched by automatic
  • CCentral patch management system where all updates are tested in a lab environment after being
  • DDistributed patch management system where all updates are tested in a lab environment prior to

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    16% (5)
  • C
    6% (2)
  • D
    74% (23)

Explanation

The scenario describes a failed patch that crashed critical servers - the lesson is that updates must be validated before reaching production. A distributed patch management system with lab testing prior to deployment satisfies both requirements: testing in a lab environment catches defective updates before they can cause downtime, and the distributed model allows phased rollouts that reduce the blast radius if an issue is missed. Option A patches production systems without testing. Option B uses central automatic patching with no testing, which mirrors what caused the original failure. Option C tests in the lab 'after' updates are applied to production, which is backwards and would not prevent downtime. Only Option D (test first, then deploy) minimizes downtime while ensuring updates reach all systems.

Topics

#patch management#lab testing#risk mitigation#change control

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice