350-201 exam dumps

350-201 practice question 69 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 69

Select 3

During a routine vulnerability assessment of your network, you discover that several Cisco devices are running outdated software that contains known vulnerabilities. Some devices are critical to business operations and cannot afford downtime, while others are less critical and can be taken offline for updates. What would be the best patching recommendation to minimize security risks while maintaining business continuity?

  1. A

    Prioritize patching the critical devices immediately, even if it causes downtime.

  2. B

    Apply patches first to less critical devices to test for potential issues before patching critical devices.

  3. C

    Implement virtual patching or intrusion prevention system (IPS) rules as a temporary measure for critical devices.

  4. D

    Delay all patching until a maintenance window is scheduled for all devices.

  5. E

    Perform a risk assessment to evaluate the impact of vulnerabilities and prioritize patching accordingly.

Show answer and explanation

Correct answers: B, C, E

Explanation

In this scenario, the optimal approach to patching involves first testing patches on less critical devices to avoid potential disruptions to critical systems. For critical devices, virtual patching or IPS rules can act as a temporary safeguard until patches can be applied during a planned maintenance window. Conducting a risk assessment ensures that patching efforts are aligned with the severity of vulnerabilities and business priorities.

  • A. Incorrect.

    Patching critical devices immediately without proper planning might cause business disruptions. It is better to assess the risk and test patches on less critical devices first.

  • B. Correct.

    Applying patches to less critical devices first can help identify potential issues and ensure patch stability before deploying to critical devices.

  • C. Correct.

    Virtual patching or IPS rules can provide a temporary layer of security, allowing critical devices to be protected until a patch can be safely applied.

  • D. Incorrect.

    Delaying all patching increases the exposure to vulnerabilities and is not recommended unless absolutely unavoidable.

  • E. Correct.

    Performing a risk assessment helps prioritize patching efforts based on the potential impact of vulnerabilities and ensures a strategic approach.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam