nerdexam
(ISC)2

CISSP · Question #191

Which of the following is a reason to use manual patch installation instead of automated patch management?

The correct answer is C. The likelihood of system or application incompatibilities will be decreased.. Manual vs. Automated Patch Management Manual patch installation is preferred when there is a higher risk of compatibility issues, because IT administrators can carefully test each patch in a controlled environment before deploying it to production systems, reducing the chance tha

Submitted by olafpl· Mar 5, 2026Security Operations

Question

Which of the following is a reason to use manual patch installation instead of automated patch management?

Options

  • AThe cost required to install patches will be reduced.
  • BThe time during which systems will remain vulnerable to an exploit will be decreased.
  • CThe likelihood of system or application incompatibilities will be decreased.
  • DThe ability to cover large geographic areas is increased.

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    91% (42)
  • D
    4% (2)

Explanation

Manual vs. Automated Patch Management

Manual patch installation is preferred when there is a higher risk of compatibility issues, because IT administrators can carefully test each patch in a controlled environment before deploying it to production systems, reducing the chance that a patch will break an existing application or cause system instability (making C correct).

Why the distractors are wrong:

  • A (cost reduction) – Manual patching is actually more expensive in terms of labor and administrative time than automated solutions
  • B (decreased vulnerability window) – Automated patching reduces the time systems remain vulnerable by deploying patches quickly and at scale; manual patching is slower
  • D (geographic coverage) – Automated patch management excels at covering large, geographically dispersed environments; manual patching is impractical at scale

Memory Tip: Think of manual patching as the "careful surgeon" approach - it's slower and more resource-intensive, but you have precise control over what gets installed and when, making it ideal when compatibility is a concern. When you see "manual," associate it with control and compatibility testing, not speed or cost savings.

Topics

#Patch Management#Vulnerability Management#Operational Security#System Compatibility

Community Discussion

No community discussion yet for this question.

Full CISSP Practice