Courseiva
mediumMultiple Choice

200-201 Practice Question: A critical security patch for a widely exploited…

A critical security patch for a widely exploited vulnerability is released. The patch requires a system reboot during business hours. According to change management policy, what is the best procedure?

⚠ Common exam trap

Cisco often tests the misconception that change management always requires waiting for a scheduled window, but the trap here is that emergency change processes exist specifically to handle critical security patches that cannot wait.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit an emergency change request for immediate approval

When a critical security patch addresses a widely exploited vulnerability, the immediate risk to the organization outweighs standard change windows. Change management policy typically includes an emergency change process that bypasses normal scheduling to allow rapid deployment with expedited approval, even if a reboot during business hours is required. This aligns with the principle of prioritizing security over availability in high-severity scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the patch only at the end of the business day

    Why it's wrong here

    Deferring to the end of the business day delays remediation of an actively exploited vulnerability, extending exposure beyond what an emergency change permits. It is tempting because it limits disruption, but it would be correct for routine patches where business-hours impact outweighs the urgency of immediate deployment.

  • ✗

    Wait for the next scheduled change window

    Why it's wrong here

    Waiting for the next scheduled window leaves a widely exploited vulnerability unpatched, contradicting the emergency change path that critical patches require. It is tempting because it follows routine change governance, but it would be correct for low-risk, non-urgent updates where no active exploitation is occurring.

  • ✓

    Submit an emergency change request for immediate approval

    Why this is correct

    An emergency change request satisfies the policy requirement for handling urgent, unplanned changes, allowing immediate approval and deployment. Because the vulnerability is widely exploited and the patch demands a business-hours reboot, standard change procedures would introduce unacceptable exposure delay; emergency change processes exist precisely to authorise such time-critical remediation.

  • ✗

    Install the patch without approval

    Why it's wrong here

    Installing without approval bypasses the change management process entirely, removing the authorisation and documentation that emergency changes still require. It is tempting because speed matters for exploited vulnerabilities, but it would be correct only under a formally invoked emergency change procedure with retrospective approval.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.