SY0-701 exam dumps

SY0-701 practice question 26 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 26

Single answer

A security team needs to deploy an emergency configuration change to a customer-facing web application after a critical vulnerability is discovered. The patch was successfully validated in a staging environment, but it requires a brief service restart. The application owner warns that an unplanned outage during business hours could interrupt payment processing and violate a partner SLA. Which of the following should the security analyst do FIRST to ensure the change is implemented in a way that aligns with business processes impacting security operations?

  1. A

    Implement the change immediately in production because the vulnerability is critical and testing has already been completed

  2. B

    Submit the change through the approval process with documented impact analysis, identified owner/stakeholders, maintenance window, and backout plan

  3. C

    Ask the system administrator to apply the patch after hours without formal documentation to reduce the chance of stakeholder objections

  4. D

    Delay the patch until the next quarterly update cycle so the standard operating procedure is not disrupted

Show answer and explanation

Correct answer: B

Explanation

The best answer is to submit the emergency change through the formal approval process with supporting documentation. In practice, security operations must balance confidentiality, integrity, and availability with business requirements. A proper change record should identify the system owner, affected stakeholders, expected impact, test results from staging, the planned maintenance window, and a backout plan if the deployment causes issues. This aligns with common change-management and security operations best practices found in frameworks such as ITIL change enablement, NIST SP 800-61 for incident-driven operational response considerations, and general organizational change-control policies. Even urgent security remediation should be documented and approved through an emergency change path rather than implemented informally or delayed unnecessarily.

  • A. Incorrect.

    This is incorrect because severity alone does not override business change management. Even for emergency changes, organizations typically require expedited approval, documented risk/impact, and coordination with owners and stakeholders. Testing in staging is important, but production deployment still needs governance, a maintenance window if downtime is expected, and a backout plan in case the change fails.

  • B. Correct.

    This is correct because it incorporates the key business processes that affect secure operations: approval process, ownership, stakeholder involvement, impact analysis, maintenance window selection, and a backout plan. Since the patch has already been tested, the next step is to formally route the emergency change so decision-makers can weigh the security risk against business disruption and ensure the rollout follows established procedures.

  • C. Incorrect.

    This is incorrect because bypassing documentation and approval creates operational and audit risk. Although after-hours deployment may reduce customer impact, informal implementation ignores ownership, stakeholder communication, and change-control requirements. A patch applied without a documented rollback path or approved maintenance window can cause larger outages and accountability problems.

  • D. Incorrect.

    This is incorrect because deferring a critical security fix until the next routine cycle may leave the organization exposed to active exploitation. Standard operating procedures should support controlled security changes, including emergency processes when justified. Waiting for a quarterly cycle is not appropriate when a validated fix is available and the risk is significant.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam