SY0-701 Question 134
Single answerPatchingA security administrator must deploy a critical operating system patch that fixes an actively exploited vulnerability on 300 Windows workstations. The organization has a formal change-management process, and several accounting systems run a legacy application that has broken after past updates. Management wants the vulnerability remediated quickly without causing a widespread outage. Which action should the administrator take FIRST?
- A
Deploy the patch immediately to all 300 workstations to minimize the exposure window
- B
Test the patch on a small group of representative systems, including accounting workstations, before broad deployment
- C
Wait until the next regularly scheduled monthly maintenance window so users have advance notice
- D
Uninstall the legacy accounting application from affected systems so the patch can be applied without compatibility concerns
Show answer and explanation
Correct answer: B
Explanation
The best answer is to test the patch on a limited pilot group of representative systems before broad deployment. Effective patch management in security operations is risk-based: organizations should prioritize critical vulnerabilities, especially those under active exploitation, but still follow controlled processes to avoid disrupting production. A common best practice is phased deployment: validate in a test environment or pilot group, include high-risk or business-critical use cases, then expand deployment after confirmation. This approach aligns with widely accepted guidance from vendors and security frameworks, including Microsoft update deployment guidance and NIST patch-management recommendations, which emphasize prioritization, testing, change control, and staged rollout. In this scenario, the known history of the accounting application breaking after updates makes representative pilot testing the most appropriate first action.
- A. Incorrect.
This is incorrect. Although rapid remediation is important for actively exploited vulnerabilities, immediately patching all systems without validation creates significant operational risk. In environments with known application compatibility issues, skipping testing can cause a large-scale outage and violate change-management best practices.
- B. Correct.
This is correct. A pilot deployment to representative systems is the best first step because it balances urgency with risk reduction. Testing on a small subset, especially systems known to run the fragile accounting application, helps identify compatibility or stability issues before enterprise-wide rollout. This reflects standard patch-management practice: assess, test, approve, and then deploy in phases.
- C. Incorrect.
This is incorrect. Deferring a critical patch for an actively exploited vulnerability until the normal maintenance window leaves the organization exposed longer than necessary. High-risk patches commonly require expedited change procedures rather than routine scheduling.
- D. Incorrect.
This is incorrect. Removing a business-critical legacy application is not an appropriate first response to patching risk. The goal is to validate the patch's impact and maintain business operations, not to eliminate the application without proper planning, approval, and likely business-owner involvement.