Courseiva
Operations and Support →mediumMultiple Select

CV0-004 Operations and Support Practice Question

An organization is using Azure and wants to implement a patch management strategy with minimal disruption. Which TWO actions should they take? (Select TWO.)

⚠ Common exam trap

CV0-004 often tests the misconception that patching all servers at once or disabling automatic updates is acceptable for minimal disruption, when in fact controlled scheduling and rollback capabilities are key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement rollback procedures

Option A (Implement rollback procedures) is correct because a rollback plan allows the organization to revert a patch that causes regressions or outages, directly supporting minimal disruption by limiting the blast radius and downtime of a failed update. Option B (Define maintenance windows for patching) is correct because scheduling patches during controlled, low-traffic periods prevents unexpected reboots and performance impacts during business hours, which is the core of a minimal-disruption patch management strategy. Option C is incorrect because relying solely on manual patching is error-prone, does not scale, and increases the risk of missed or inconsistently applied updates. Option D is incorrect because patching all servers simultaneously maximizes the chance of a widespread outage and removes the ability to validate patches on a subset first. Option E is incorrect because disabling automatic updates on all VMs leaves systems unpatched and exposed to known vulnerabilities, contradicting a sound patch management strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement rollback procedures

    Why this is correct

    Rollback procedures directly satisfy the minimal-disruption constraint: if a patch breaks a workload, reverting to the pre-patch state restores service quickly rather than waiting for a vendor fix. Combined with staged deployment, this limits blast radius across Azure VMs, making recovery a planned, tested step rather than an outage.

  • ✓

    Define maintenance windows for patching

    Why this is correct

    Maintenance windows schedule patching during low-traffic periods, directly satisfying the minimal-disruption constraint. Azure Update Manager applies updates only within these defined windows, preventing unexpected reboots during peak hours and giving operations teams predictable control over when production workloads are affected.

  • ✗

    Use only manual patching

    Why it's wrong here

    Manual patching alone cannot scale across an Azure estate and leaves gaps between cycles, so it cannot deliver minimal disruption. It appeals when change control demands approval before every update, but Azure Update Manager or Automation Update Management provides scheduled, orchestrated patching with maintenance windows instead.

  • ✗

    Patch all servers simultaneously

    Why it's wrong here

    Patching every server at once causes simultaneous reboots and outages, directly violating minimal disruption. It appeals as the fastest route to full compliance, but the correct approach staggers updates across availability sets or update rings so workloads remain available while patching proceeds.

  • ✗

    Disable automatic updates on all VMs

    Why it's wrong here

    Disabling automatic updates leaves guest OS and application vulnerabilities unpatched, contradicting the goal of a managed strategy. It appeals where updates have previously broken workloads, yet the correct approach is controlled scheduling through Update Manager with maintenance windows and staged rings, not blanket suppression.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.