nerdexam
CompTIA

SY0-301 · Question #199

A system administrator has noticed vulnerability on a high impact production server. A recent update was made available by the vendor that addresses the vulnerability but requires a reboot of the…

The correct answer is C. Test the update in a lab environment, backup the server, schedule downtime to install the patch, install. The correct patch management process for a high-impact production server is: (1) Test the patch in a lab environment to verify it doesn't break functionality, (2) Back up the server to enable recovery if the patch causes issues, (3) Schedule a maintenance window/downtime to…

Security operations

Question

A system administrator has noticed vulnerability on a high impact production server. A recent update was made available by the vendor that addresses the vulnerability but requires a reboot of the system afterwards. Which of the following steps should the system administrator implement to address the vulnerability?

Options

  • ATest the update in a lab environment, schedule downtime to install the patch, install the patch and
  • BTest the update in a lab environment, backup the server, schedule downtime to install the patch, install
  • CTest the update in a lab environment, backup the server, schedule downtime to install the patch, install
  • DBackup the server, schedule downtime to install the patch, installs the patch and monitor for any changes

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    81% (25)
  • D
    10% (3)

Explanation

The correct patch management process for a high-impact production server is: (1) Test the patch in a lab environment to verify it doesn't break functionality, (2) Back up the server to enable recovery if the patch causes issues, (3) Schedule a maintenance window/downtime to minimize business impact, (4) Install the patch, (5) Reboot as required, and (6) Monitor the system afterward for any unexpected behavior or regressions. Skipping the backup step (option D) is risky for a high-impact server. Testing must come before backup and deployment to confirm the patch is safe. Monitoring after deployment ensures the patch didn't introduce new issues.

Topics

#patch management#vulnerability remediation#change management#backup procedures

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice