Courseiva
mediumMultiple ChoiceObjective-mapped

CS0-003 Practice Question: Uses automated patch management for workstations…

An organization uses automated patch management for workstations but manual patching for servers. After a critical vulnerability is announced, the security team wants to expedite patching for servers. Which of the following is the BEST approach?

⚠ Common exam trap

A common mix-up: candidates choose immediate deployment (Option C) due to the urgency of a critical vulnerability, overlooking the operational risk of untested patches in a manual patching environment, while CompTIA often tests the principle that security must be balanced with availability and change management processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Test the patch in a staging environment and then deploy

Testing the patch in a staging environment before deploying to production servers validates compatibility and stability, reducing the risk of service disruption. This approach balances the urgency of a critical vulnerability with the need to maintain server availability, which is especially important given that manual patching is the standard procedure for servers. Staging allows the security team to identify any conflicts with existing configurations or dependencies before widespread deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Test the patch in a staging environment and then deploy

    Why this is correct

    Testing a patch in a staging environment is the most prudent and recommended practice before deploying it to production systems, especially with automated patch management. This process allows administrators to thoroughly evaluate the patch's compatibility with existing applications and configurations, identify potential regressions, and confirm its effectiveness in a controlled, non-production setting. This crucial step minimizes the risk of introducing new vulnerabilities, system instability, or service outages that could arise from an untested patch in a live environment.

  • Disable the affected services until the patch can be applied

    Why it's wrong here

    Disabling affected services until a patch can be applied, while potentially mitigating immediate exploitation, is generally an undesirable primary remediation strategy due to its severe impact on business continuity. This action directly disrupts critical operations, leading to significant downtime, loss of productivity, and potential financial repercussions. It should only be considered as an extreme, last-resort measure when no other immediate protective controls are feasible and the threat risk is exceptionally high, rather than a standard patching procedure.

  • Deploy the patch immediately to all servers

    Why it's wrong here

    Deploying a patch immediately to all servers without prior testing or a phased rollout strategy carries substantial risk and is a highly ill-advised approach. An untested patch could contain unforeseen bugs, introduce compatibility issues with existing applications, or even create new vulnerabilities, leading to widespread system instability, service outages, or data corruption across the entire infrastructure. This aggressive deployment method bypasses critical validation steps, potentially transforming a localized issue into a catastrophic enterprise-wide failure.

  • Implement virtual patching via an IPS

    Why it's wrong here

    Implementing virtual patching via an Intrusion Prevention System (IPS) is a valuable compensating control that can provide temporary protection against known vulnerabilities by inspecting and blocking malicious traffic attempting to exploit them. However, it is not a primary remediation for the underlying vulnerability itself. Virtual patching does not fix the flawed code; it merely acts as a protective layer, meaning the system remains vulnerable if the IPS is bypassed or misconfigured, necessitating actual software patching as the definitive solution.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.