nerdexam
Isaca

CISM · Question #18

A software vendor has announced a zero-day vulnerability that exposes an organization's critical business systems. The vendor has released an emergency patch. Which of the following should be the…

The correct answer is A. Ability to test the patch prior to deployment. The primary concern for an information security manager during an emergency patch deployment for a zero-day vulnerability is ensuring the patch does not introduce new instability or issues.

Submitted by kwame.gh· Apr 18, 2026Information Security Risk Management

Question

A software vendor has announced a zero-day vulnerability that exposes an organization’s critical business systems. The vendor has released an emergency patch. Which of the following should be the information security manager’s PRIMARY concern?

Options

  • AAbility to test the patch prior to deployment
  • BAdequacy of the incident response plan
  • CAvailability of resources to implement controls
  • DDocumentation of patching procedures

How the community answered

(18 responses)
  • A
    83% (15)
  • B
    6% (1)
  • C
    11% (2)

Why each option

The primary concern for an information security manager during an emergency patch deployment for a zero-day vulnerability is ensuring the patch does not introduce new instability or issues.

AAbility to test the patch prior to deploymentCorrect

While immediate deployment might seem critical for a zero-day, deploying an untested emergency patch without proper validation can introduce severe system instability, operational disruptions, or new vulnerabilities. The primary concern is balancing the need for speed with the imperative to maintain system stability and functionality, necessitating at least minimal testing.

BAdequacy of the incident response plan

Adequacy of the incident response plan is important, but the immediate concern during a *patch deployment* is the patch itself and its impact, assuming the zero-day *has* been found.

CAvailability of resources to implement controls

Availability of resources to implement controls is a logistical concern, but the technical validity and safety of the patch itself take precedence over resource allocation during critical decision-making.

DDocumentation of patching procedures

Documentation of patching procedures is an administrative task that follows or runs concurrently with the actual patch deployment, not the primary concern during an emergency.

Concept tested: Emergency patch management considerations

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines/patch-management-process

Topics

#Zero-day vulnerability#Patch management#Risk assessment#Emergency response

Community Discussion

No community discussion yet for this question.

Full CISM Practice