Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

A company manages 300 laptops and wants to reduce risk from missed patches while avoiding a widespread outage if an update has compatibility issues. Which patching approach is the best choice?

⚠ Common exam trap

It's easy for candidates to choose Option B (immediate deployment) because they prioritize speed and simplicity over risk management, failing to recognize that unvalidated patches can cause cascading failures that negate any security benefits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a phased rollout with a pilot group, then expand deployment after validation, while keeping a standard baseline configuration.

A phased rollout with a pilot group allows the IT team to validate patches on a small subset of laptops before full deployment, reducing the risk of widespread outages from compatibility issues. Maintaining a standard baseline configuration ensures consistency across all 300 laptops, which simplifies patch management and reduces the likelihood of missed patches. This approach balances risk mitigation with operational continuity, aligning with best practices for enterprise patch management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Install patches manually on each laptop after users report problems.

    Why it's wrong here

    This approach is inherently reactive and depends on end users to detect issues, which means vulnerabilities can be exploited for weeks or months before anyone notices. Manual per-laptop installation also introduces configuration drift, as each device may receive different updates at different times depending on user reports. Without a centralized patch management system and a known-good baseline, the organization loses visibility into the security posture of its fleet.

  • Deploy all patches to every laptop immediately with no testing.

    Why it's wrong here

    Untested mass deployment of all patches to every laptop simultaneously is risky because a single problematic patch can break critical business applications or cause driver conflicts across the entire fleet at once. Security patches are not inherently safe; they can introduce new stability or compatibility issues. A lack of staged rollout means there is no opportunity to validate the patch on a small subset first, potentially leading to widespread operational downtime that outweighs the short-term security benefit.

  • Use a phased rollout with a pilot group, then expand deployment after validation, while keeping a standard baseline configuration.

    Why this is correct

    A phased or ring-based rollout balances speed and stability. A pilot group catches compatibility issues early, and the baseline keeps endpoint settings consistent across the fleet. This approach reduces risk from vulnerabilities without creating unnecessary operational disruption.

  • Wait for annual maintenance windows so all changes happen at once.

    Why it's wrong here

    Waiting for annual maintenance windows means known vulnerabilities remain unmitigated for up to a year, which is unacceptable for a fleet of 300 laptops and far outside the typical patch cadence. This approach treats patching as a static, once-a-year event rather than an ongoing risk management process, and it fails to account for zero-day exploits and emerging threats. Additionally, bundling all changes into a large annual batch increases the risk of deployment failures and makes troubleshooting more difficult.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.