CAS-003 · Question #552
The security configuration management policy states that all patches must undergo testing procedures before being moved into production. The security analyst notices a single web application server…
The correct answer is C. Create an incident ticket for anomalous activity. A server autonomously downloading and applying patches in violation of the organization's change management policy is anomalous activity that must be documented as an incident regardless of apparent impact.
Question
The security configuration management policy states that all patches must undergo testing procedures before being moved into production. The security analyst notices a single web application server has been downloading and applying patches during non-business hours without testing. There are no apparent adverse reactions, server functionality does not seem to be affected, and no malware was found after a scan. Which of the following actions should the analyst take?
Options
- AReschedule the automated patching to occur during business hours.
- BMonitor the web application service for abnormal bandwidth consumption.
- CCreate an incident ticket for anomalous activity.
- DMonitor the web application for service interruptions caused from the patching.
How the community answered
(52 responses)- A23% (12)
- B6% (3)
- C58% (30)
- D13% (7)
Why each option
A server autonomously downloading and applying patches in violation of the organization's change management policy is anomalous activity that must be documented as an incident regardless of apparent impact.
Rescheduling the automated patching to business hours does not address the core policy violation, which is that patches are being applied without required testing.
Monitoring for abnormal bandwidth is insufficient as a sole response because it does not investigate or remediate the unauthorized configuration that is bypassing the patch testing requirement.
Security configuration management policy explicitly mandates that all patches undergo testing before production deployment, and a server bypassing this process constitutes a policy violation and an unauthorized change that must be formally tracked. Creating an incident ticket initiates the proper investigation to determine how the server's update settings were misconfigured or tampered with, ensuring accountability and preventing recurrence. Documenting the event is required even when no immediate harm is observed, because the policy breach itself is the security concern.
Monitoring for service interruptions is a reactive measure that ignores the policy violation and does not investigate the root cause of the unauthorized automated patching.
Concept tested: Incident response for patch management policy violations
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-vulnerability-management
Topics
Community Discussion
No community discussion yet for this question.