SY0-701 exam dumps

SY0-701 practice question 135 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 135

Single answerPatching

A security administrator learns that a critical remote code execution vulnerability is being actively exploited against the organization's VPN appliance. The vendor has released a security patch, but the appliance supports remote employees and cannot tolerate extended downtime during business hours. Which action should the administrator take FIRST to reduce organizational risk while following sound patch-management practices?

  1. A

    Schedule an emergency maintenance window, back up the appliance configuration, validate the patch in a test or staging environment if available, and then deploy the vendor patch as soon as possible

  2. B

    Wait until the next regular monthly patch cycle so the change can go through the normal process without exceptions

  3. C

    Disable all logging on the appliance to improve performance during the patch and reduce the chance of failure

  4. D

    Reboot the appliance daily until the vendor releases a more stable version of the patch

Show answer and explanation

Correct answer: A

Explanation

For patching, Security+ expects candidates to understand risk-based prioritization, testing, backups, change management, and the need for emergency processes when critical vulnerabilities are actively exploited. Best practice is to assess the severity and exposure of the affected asset, use an emergency change window when justified, ensure rollback capability through backups or snapshots where appropriate, validate the patch in a staging environment if available, and then deploy promptly. This is especially important for internet-facing infrastructure such as VPN gateways. Guidance from vendor security advisories, CISA Known Exploited Vulnerabilities practices, and common change-management frameworks supports accelerated remediation for critical, exploited issues rather than waiting for a normal patch cycle.

  • A. Correct.

    This is the best answer because actively exploited critical vulnerabilities on internet-facing systems require expedited remediation. Sound patch-management practice includes using an emergency change process, taking a current backup or configuration export, testing when feasible, and deploying the vendor-approved patch promptly to reduce exposure. This balances availability concerns with the need to address a high-risk security issue.

  • B. Incorrect.

    This is incorrect because delaying remediation of an actively exploited critical vulnerability on a public-facing VPN appliance leaves the organization exposed unnecessarily. Regular patch cycles are appropriate for routine updates, but severe vulnerabilities commonly require out-of-band or emergency patching.

  • C. Incorrect.

    This is incorrect because disabling logging does not reduce security risk from the vulnerability and weakens detection, troubleshooting, and post-change validation. Logging is important before, during, and after patching to confirm system behavior and identify any issues.

  • D. Incorrect.

    This is incorrect because rebooting alone does not remediate a software vulnerability unless the patch has already been applied and requires a restart. Relying on reboots instead of installing the vendor fix is a common but ineffective misconception.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam