312-50 exam dumps

312-50 practice question 294 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 294

Single answer▪ Patch Management

During an authorized internal assessment, a CEH discovers that several Windows servers are missing a critical security update that fixes a publicly known remote code execution vulnerability. The systems host a revenue-generating application, and the operations team refuses immediate deployment because they fear downtime. Management asks the CEH for the best next step that reduces risk while following sound patch management practice. What should the CEH recommend?

  1. A

    Deploy the patch directly to all production servers immediately, because critical patches should bypass normal change control when exploitation is possible

  2. B

    Document the affected assets, verify exposure and business impact, test the patch in a staging environment, and implement compensating controls until the approved rollout window

  3. C

    Delay action until the next quarterly maintenance cycle, because unplanned patching creates more operational risk than a known vulnerability

  4. D

    Remove the vulnerability from the report if there is no evidence that attackers have already exploited the servers

Show answer and explanation

Correct answer: B

Explanation

Effective patch management is not just about installing updates; it is about reducing risk in a controlled and auditable way. In this scenario, the CEH should recommend a process that aligns with common security and operations best practices: asset identification, vulnerability validation, risk prioritization, patch testing, change management, and compensating controls when immediate deployment is not feasible. This is consistent with guidance from NIST, including the Risk Management Framework and vulnerability management practices, as well as general enterprise change management principles. For critical remote code execution issues, compensating controls may include network segmentation, blocking vulnerable ports, restricting internet exposure, increasing monitoring, or disabling the affected service temporarily. The key exam point is that ethical hackers should provide realistic remediation advice that balances exploitability, business impact, and operational constraints rather than recommending reckless immediate deployment or unjustified delay.

  • A. Incorrect.

    This is incorrect. Even for critical vulnerabilities, pushing patches straight to production without validation can cause outages, application incompatibility, or failed rollbacks. Mature patch management requires risk-based prioritization, testing, change approval, and deployment planning. Emergency change processes may exist, but they still do not justify skipping assessment and validation entirely.

  • B. Correct.

    This is correct. The best recommendation is a risk-based patch management approach: identify and document affected systems, confirm the vulnerability and likely exposure, assess business impact, test the fix in a non-production environment, and use compensating controls such as firewall restrictions, IPS signatures, service hardening, or temporary isolation until deployment is approved. This balances security urgency with operational stability and reflects real-world enterprise patch governance.

  • C. Incorrect.

    This is incorrect. Deferring a critical remotely exploitable vulnerability until a routine maintenance cycle is poor practice when the risk is active and well understood. Quarterly scheduling may be appropriate for low-risk updates, but critical security patches often require expedited handling, especially when public exploit information exists.

  • D. Incorrect.

    This is incorrect. Lack of confirmed exploitation does not eliminate risk. Vulnerability reporting should reflect the presence of the exposure, not just evidence of compromise. Removing it from the report would undermine remediation and give management an inaccurate picture of the organization's security posture.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam