nerdexam
CompTIA

SK0-003 · Question #411

An administrator needs to implement a security patch policy on the network that adheres to an internal SLA. Which of the following actions BEST achieves this task?

The correct answer is A. Define a test server group, install the patches and if successful schedule installation on. To comply with an SLA for security patching, the best practice is to first test patches on a designated group of non-production servers before deploying them widely to production.

Server administration

Question

An administrator needs to implement a security patch policy on the network that adheres to an internal SLA. Which of the following actions BEST achieves this task?

Options

  • ADefine a test server group, install the patches and if successful schedule installation on
  • BDefine a test server group, schedule installation on production servers and then install all
  • CInstall the patches during a non-working hour.
  • DSend an email to all company users and request the best time for installation.

How the community answered

(17 responses)
  • A
    71% (12)
  • B
    18% (3)
  • C
    6% (1)
  • D
    6% (1)

Why each option

To comply with an SLA for security patching, the best practice is to first test patches on a designated group of non-production servers before deploying them widely to production.

ADefine a test server group, install the patches and if successful schedule installation onCorrect

Defining a test server group and successfully installing patches there before scheduling installation on production servers minimizes the risk of introducing issues that could violate an SLA by disrupting critical services. This phased approach ensures stability and adherence to service level agreements.

BDefine a test server group, schedule installation on production servers and then install all

Scheduling installation on production servers before successfully installing patches on a test group bypasses crucial validation, risking production outages or issues that could violate SLAs.

CInstall the patches during a non-working hour.

Installing patches only during non-working hours without prior testing on a test group still carries the risk of unforeseen issues in production systems, potentially violating an SLA.

DSend an email to all company users and request the best time for installation.

Sending an email to users for patch scheduling is inefficient and does not address the technical validation or risk management required to meet an internal SLA for security patches.

Concept tested: Patch management best practices

Source: https://learn.microsoft.com/en-us/windows-server/get-started/patch-management-best-practices

Topics

#Patch management#Security policy#SLA#Change management

Community Discussion

No community discussion yet for this question.

Full SK0-003 Practice