SY0-701 exam dumps

SY0-701 practice question 25 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 25

Single answer

A security administrator needs to deploy an emergency change to a production web application after a critical vulnerability is discovered in a third-party component. The patch has passed testing in staging, but applying it in production will require a service restart that could interrupt customer transactions. The application is owned by the e-commerce team, and several business units rely on the platform for revenue. The change request includes the test results and a proposed maintenance window, but leadership is concerned about business disruption if the deployment fails. Which of the following should be completed NEXT to best support a secure and well-governed production change?

  1. A

    Obtain approval from the change authority and confirm a documented backout plan before implementation

  2. B

    Deploy the patch immediately because the vulnerability is critical and testing has already been completed

  3. C

    Ask the SOC manager to monitor the deployment and decide during the change whether a rollback is necessary

  4. D

    Wait to patch until the next standard maintenance cycle so all stakeholders can review it during the monthly meeting

Show answer and explanation

Correct answer: A

Explanation

This question focuses on business processes that affect security operations in real-world change management. The scenario includes several required elements already in progress: ownership is identified, stakeholders are implied by the multiple business units, test results exist, and a maintenance window has been proposed. The remaining key governance step is to complete the approval process and ensure a documented backout plan exists before implementation. In practice, organizations commonly use formal change management processes aligned with ITIL-style change control, where emergency changes can be expedited but still require authorization, impact analysis, communication to stakeholders, implementation planning, and rollback procedures. Standard operating procedures should define who approves the change, who owns the system, how impact is assessed, how testing is documented, what the maintenance window is, and how to revert if production issues occur. For Security+, candidates should recognize that secure operations are not just about applying fixes quickly; they also require coordination, accountability, and minimizing business disruption.

  • A. Correct.

    Correct. In a controlled security operation, even urgent production changes should follow the organization's approval process and include a documented backout plan. The scenario already states that test results and a maintenance window are prepared, but leadership is specifically concerned about the impact of failure. A backout plan addresses that concern by defining how to restore service if the change causes issues. Approval from the appropriate change authority or stakeholders ensures accountability, ownership alignment, and business sign-off before affecting a revenue-generating system.

  • B. Incorrect.

    Incorrect. A critical vulnerability can justify an expedited change process, but not bypassing governance entirely. Testing in staging is important, but production changes still require approval, stakeholder awareness, and a rollback strategy. Deploying immediately without those controls increases operational and business risk, especially for a system with customer-facing transactions.

  • C. Incorrect.

    Incorrect. Monitoring during deployment is useful, but the SOC manager is not necessarily the system owner or the proper approval authority for a production application change. Deciding on rollback ad hoc during the change is weaker than having a documented backout plan established in advance. This option confuses operational monitoring with formal change governance.

  • D. Incorrect.

    Incorrect. Deferring a patch for a critical vulnerability until the next routine maintenance meeting may leave the organization exposed unnecessarily. Security best practices support expedited emergency changes when risk is high, provided they still include approval, ownership, impact consideration, and rollback planning. Waiting for the normal cycle is too slow for the scenario described.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam