mediumMultiple ChoiceObjective-mapped
CS0-003 Practice Question: Uses automated patch management for workstations…
An organization uses automated patch management for workstations but manual patching for servers. After a critical vulnerability is announced, the security team wants to expedite patching for servers. Which of the following is the BEST approach?
⚠ Common exam trap
A common mix-up: candidates choose immediate deployment (Option C) due to the urgency of a critical vulnerability, overlooking the operational risk of untested patches in a manual patching environment, while CompTIA often tests the principle that security must be balanced with availability and change management processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test the patch in a staging environment and then deploy
Testing the patch in a staging environment before deploying to production servers validates compatibility and stability, reducing the risk of service disruption. This approach balances the urgency of a critical vulnerability with the need to maintain server availability, which is especially important given that manual patching is the standard procedure for servers. Staging allows the security team to identify any conflicts with existing configurations or dependencies before widespread deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Test the patch in a staging environment and then deploy
Why this is correct
Testing a patch in a staging environment is the most prudent and recommended practice before deploying it to production systems, especially with automated patch management. This process allows administrators to thoroughly evaluate the patch's compatibility with existing applications and configurations, identify potential regressions, and confirm its effectiveness in a controlled, non-production setting. This crucial step minimizes the risk of introducing new vulnerabilities, system instability, or service outages that could arise from an untested patch in a live environment.
- ✗
Disable the affected services until the patch can be applied
Why it's wrong here
Disabling affected services until a patch can be applied, while potentially mitigating immediate exploitation, is generally an undesirable primary remediation strategy due to its severe impact on business continuity. This action directly disrupts critical operations, leading to significant downtime, loss of productivity, and potential financial repercussions. It should only be considered as an extreme, last-resort measure when no other immediate protective controls are feasible and the threat risk is exceptionally high, rather than a standard patching procedure.
- ✗
Deploy the patch immediately to all servers
Why it's wrong here
Deploying a patch immediately to all servers without prior testing or a phased rollout strategy carries substantial risk and is a highly ill-advised approach. An untested patch could contain unforeseen bugs, introduce compatibility issues with existing applications, or even create new vulnerabilities, leading to widespread system instability, service outages, or data corruption across the entire infrastructure. This aggressive deployment method bypasses critical validation steps, potentially transforming a localized issue into a catastrophic enterprise-wide failure.
- ✗
Implement virtual patching via an IPS
Why it's wrong here
Implementing virtual patching via an Intrusion Prevention System (IPS) is a valuable compensating control that can provide temporary protection against known vulnerabilities by inspecting and blocking malicious traffic attempting to exploit them. However, it is not a primary remediation for the underlying vulnerability itself. Virtual patching does not fix the flawed code; it merely acts as a protective layer, meaning the system remains vulnerable if the IPS is bypassed or misconfigured, necessitating actual software patching as the definitive solution.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Patch management
Patch management is the process of identifying, acquiring, testing, and deploying software updates (patches) to fix vulnerabilities, bugs, or improve performance in IT systems.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.