220-1102 Question 506
Single answerPatch managementA technician manages 40 Windows 11 laptops used by a small accounting firm. Last month, a problematic application update caused downtime during tax processing. Management now wants a patch management approach that reduces business risk while still addressing security vulnerabilities quickly. Which action should the technician take FIRST when implementing the new process?
- A
Deploy all operating system and application patches to every laptop immediately after release to minimize exposure
- B
Create a small pilot group of representative systems, test patches there first, and then approve broader deployment if no issues are found
- C
Disable automatic updates on all laptops and install patches manually only during annual maintenance windows
- D
Prioritize feature updates before security updates so users receive the newest functionality as soon as possible
Show answer and explanation
Correct answer: B
Explanation
A sound patch management process includes assessment, testing, approval, deployment, and verification. In this scenario, the key issue is balancing security with reliability after a previous bad update caused downtime. The best first action is to establish a pilot testing phase using representative devices and workloads. This helps identify compatibility problems before full deployment. After successful testing, patches can be rolled out in phases to the rest of the environment. This approach aligns with common IT operational best practices and Microsoft guidance for managed update deployments, where organizations often use rings or phased deployment strategies to validate updates before broad release. Security patches should still be applied in a timely manner, but controlled testing reduces the risk of repeating a widespread outage.
- A. Incorrect.
This is incorrect because immediately deploying every patch to all endpoints increases the chance that a bad update will affect the entire organization at once. While rapid patching is important for security, best practice is to validate updates in a controlled manner first, especially after a recent outage caused by an update.
- B. Correct.
This is correct because using a pilot or test group is a standard patch management best practice. It allows the technician to verify that updates do not break critical accounting applications before organization-wide deployment. This balances security with operational stability and is a practical first step in creating a safer patch process.
- C. Incorrect.
This is incorrect because disabling automatic updates broadly and waiting for annual maintenance leaves systems exposed to known vulnerabilities for too long. Patch management should reduce risk, not create long windows of exposure. Manual annual patching is not appropriate for modern security needs.
- D. Incorrect.
This is incorrect because security updates should generally be prioritized over feature updates. Feature updates may add functionality, but they do not usually address immediate security risks. In a business environment concerned with minimizing downtime and protecting systems, testing and prioritizing security-related patches is more important.