350-201 exam dumps

350-201 practice question 72 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 72

Select 3

You are a security administrator for a medium-sized organization. During a routine vulnerability scan, you identify that several devices in your network are running outdated software versions with known vulnerabilities. Some of these devices are mission-critical and cannot afford extended downtime. Which patching recommendations should you provide to address this issue?

  1. A

    Deploy patches to all devices immediately, regardless of downtime concerns.

  2. B

    Prioritize patching based on the severity of the vulnerabilities and the criticality of the devices.

  3. C

    Implement virtual patching through security controls like IPS (Intrusion Prevention System) for devices where immediate patching is not feasible.

  4. D

    Postpone all patching until a maintenance window can be scheduled for all devices.

  5. E

    Test patches in a controlled environment before deploying them to production systems.

Show answer and explanation

Correct answers: B, C, E

Explanation

Effective patch management involves prioritizing vulnerabilities, especially for mission-critical systems, while minimizing operational impact. Prioritizing patches based on severity and criticality ensures the most pressing risks are addressed first. When immediate patching is not feasible, virtual patching can provide temporary protection. Additionally, testing patches in a controlled environment ensures that they do not introduce unintended issues into production.

  • A. Incorrect.

    Deploying patches to all devices immediately without considering downtime concerns could result in disruptions to mission-critical operations, which is not a recommended approach.

  • B. Correct.

    Prioritizing patching based on severity and device criticality ensures that the most critical vulnerabilities are addressed first while minimizing potential business impact.

  • C. Correct.

    Implementing virtual patching is an effective temporary solution for devices that cannot be immediately patched, as it helps mitigate risk without requiring immediate downtime.

  • D. Incorrect.

    Postponing all patching until a maintenance window for all devices delays addressing critical vulnerabilities, leaving systems exposed for longer periods.

  • E. Correct.

    Testing patches in a controlled environment reduces the risk of introducing issues into production systems, which is a best practice in patch management.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam