CAS-001 · Question #62
The Chief Information Officer (CIO) of Company XYZ has returned from a large IT conference where one of the topics was defending against zero day attacks ?specifically deploying third party patches…
The correct answer is A. The company does not have an adequate test environment to validate the impact of the third. Without a test environment, the organization cannot validate a third-party patch before production deployment, making unverified behavior the greatest risk.
Question
The Chief Information Officer (CIO) of Company XYZ has returned from a large IT conference where one of the topics was defending against zero day attacks ?specifically deploying third party patches to vulnerable software. Two months prior, the majority of the company systems were compromised because of a zero day exploit. Due to budget constraints the company only has operational systems. The CIO wants the Security Manager to research the use of these patches. Which of the following is the GREATEST concern with the use of a third party patch to mitigate another un-patched vulnerability?
Options
- AThe company does not have an adequate test environment to validate the impact of the third
- BThe third party patch may introduce additional unforeseen risks and void the software licenses
- CThe company's patch management solution only supports patches and updates released directly
- DAnother period of vulnerability will be introduced because of the need to remove the third party patch
How the community answered
(53 responses)- A72% (38)
- B6% (3)
- C9% (5)
- D13% (7)
Why each option
Without a test environment, the organization cannot validate a third-party patch before production deployment, making unverified behavior the greatest risk.
Patch management best practice requires validating any patch in an isolated test environment before production deployment to confirm it does not break functionality or introduce new vulnerabilities. Without that environment, the company has no basis for knowing whether the third-party patch is safe to apply, making this the most critical operational concern. All other risks are secondary to deploying an untested change to production systems.
Potential license voidance and added risk from a third-party patch are real concerns, but they are secondary to the inability to test the patch's behavior before deployment.
Incompatibility with the existing patch management solution is a process limitation that can be handled manually and does not represent the greatest risk.
A temporary vulnerability window when removing a third-party patch is a minor, manageable risk compared to deploying an entirely untested patch to production systems.
Concept tested: Patch management testing and third-party patch risk assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-4/final
Topics
Community Discussion
No community discussion yet for this question.