312-50 exam dumps

312-50 practice question 296 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 296

Single answer▪ Patch Management

During an internal security assessment, an ethical hacker discovers that several Windows servers in a finance network are missing a recently released security update for a remotely exploitable vulnerability. The systems host a legacy accounting application, and the operations team is reluctant to patch immediately because of uptime concerns. The CISO asks for the MOST appropriate next step that balances security risk with patch management best practices. What should the ethical hacker recommend?

  1. A

    Deploy the patch directly to all affected production servers immediately, because security updates should take priority over application stability concerns

  2. B

    Ignore the missing patch because a vulnerability is not a practical risk until exploitation is observed in the organization

  3. C

    Test the patch in a staging environment that mirrors production, validate the legacy application's functionality, then roll out the patch using a risk-based deployment plan with compensating controls for any temporary delay

  4. D

    Wait until the next annual maintenance window so the team can bundle this update with all other pending patches and reduce operational overhead

Show answer and explanation

Correct answer: C

Explanation

Effective patch management is not just about applying updates; it is about reducing risk in a controlled and repeatable way. In a CEH context, the ethical hacker should recommend a process that accounts for exploitability, asset criticality, business impact, and operational stability. Industry best practices from sources such as NIST guidance on vulnerability and patch management emphasize maintaining an inventory of assets, prioritizing vulnerabilities based on risk, testing patches before deployment when feasible, and using compensating controls when immediate remediation is not possible. For critical remotely exploitable flaws, delaying action without mitigation is poor practice. The most appropriate recommendation is therefore to test the patch in a production-like environment, validate the legacy application's behavior, and then deploy it according to a prioritized change plan while reducing exposure through temporary safeguards if needed.

  • A. Incorrect.

    This is not the best recommendation. While critical security patches often require urgent action, applying them directly to production without validation can cause outages or break business-critical applications, especially on legacy systems. Proper patch management includes testing, change control, and prioritization rather than bypassing operational safeguards.

  • B. Incorrect.

    This is incorrect because the absence of observed exploitation internally does not reduce the severity of a known remotely exploitable vulnerability. Patch management is based on risk exposure, asset criticality, exploitability, and vendor guidance, not only on whether exploitation has already been detected in the local environment.

  • C. Correct.

    This is the best answer. A staging or test environment should be used to validate patch compatibility with the legacy accounting application before production deployment. Because the flaw is remotely exploitable, the organization should use a risk-based approach to prioritize the update and, if immediate deployment is delayed, implement compensating controls such as network segmentation, restricting exposed services, enhanced monitoring, temporary firewall rules, or IPS signatures. This balances security urgency with operational stability.

  • D. Incorrect.

    This is incorrect because deferring a critical security patch until an annual maintenance window exposes the organization to unnecessary risk. Bundling updates may reduce administrative effort, but for high-risk vulnerabilities, patch timelines should be driven by threat and business impact rather than convenience alone.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam