SY0-701 Question 24
Single answer1.3 Explain the importance of change management processes and the impact to security.A security administrator needs to deploy a critical update to the company's internet-facing VPN gateways after a vendor advisory warns of active exploitation. The update will require a reboot of each gateway and could interrupt remote access for employees. Management wants the patch applied as quickly as possible, but the organization has experienced outages in the past from rushed infrastructure changes. Which action should the administrator take FIRST to best support security and availability while following sound change management practices?
- A
Apply the update immediately to all VPN gateways during business hours so the vulnerability is closed as fast as possible
- B
Submit an emergency change request that includes risk assessment, stakeholder notification, testing/rollback steps, and an implementation window
- C
Delay the update until the next regularly scheduled maintenance cycle so the organization can avoid unplanned downtime
- D
Update one gateway without documentation and monitor for issues before deciding whether to patch the remaining systems
Show answer and explanation
Correct answer: B
Explanation
The best answer is to use an emergency change process rather than bypassing change management or delaying unnecessarily. In security operations, change management exists to reduce risk from both vulnerabilities and the changes made to fix them. For a critical, actively exploited flaw on an internet-facing VPN gateway, the organization should act quickly, but in a controlled manner. Sound practice includes documenting the reason for the change, assessing business and security impact, obtaining appropriate emergency approval, notifying stakeholders of expected downtime, scheduling implementation to minimize disruption, validating success, and maintaining a rollback/backout plan in case the update causes instability. This aligns with common IT service management and security governance practices, such as maintaining documented change procedures, approvals, impact analysis, and rollback planning. From a Security+ perspective, this demonstrates the importance of change management processes in preserving availability, accountability, and security during urgent remediation.
- A. Incorrect.
This is incorrect because it prioritizes speed without proper change control. Even for urgent security patches, applying changes to all production VPN gateways during business hours without coordination, communication, or rollback planning can create a self-inflicted outage and bypass required approval and documentation. Emergency changes still need structured review and implementation steps.
- B. Correct.
This is correct because it reflects proper emergency change management. A high-risk, actively exploited VPN vulnerability justifies expedited handling, but the change should still include documented risk analysis, affected-system scope, stakeholder communication, testing where feasible, a backout plan, and a defined implementation window. This approach reduces security exposure while preserving availability and accountability.
- C. Incorrect.
This is incorrect because deferring a critical patch for an internet-facing system with active exploitation can leave the organization exposed to compromise. Standard maintenance windows are useful, but change management should support emergency changes when the risk of waiting exceeds the risk of expedited deployment.
- D. Incorrect.
This is incorrect because testing a phased deployment can be reasonable, but performing the change without documentation or formal approval violates change management principles. The issue is not the limited rollout itself; the problem is bypassing records, communication, and rollback planning, which undermines security governance and incident traceability.