SY0-701 Security Architecture Practice Question
A company manages 300 laptops and wants to reduce risk from missed patches while avoiding a widespread outage if an update has compatibility issues. Which patching approach is the best choice?
⚠ Common exam trap
It's easy for candidates to choose Option B (immediate deployment) because they prioritize speed and simplicity over risk management, failing to recognize that unvalidated patches can cause cascading failures that negate any security benefits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a phased rollout with a pilot group, then expand deployment after validation, while keeping a standard baseline configuration.
A phased rollout with a pilot group allows the IT team to validate patches on a small subset of laptops before full deployment, reducing the risk of widespread outages from compatibility issues. Maintaining a standard baseline configuration ensures consistency across all 300 laptops, which simplifies patch management and reduces the likelihood of missed patches. This approach balances risk mitigation with operational continuity, aligning with best practices for enterprise patch management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install patches manually on each laptop after users report problems.
Why it's wrong here
This approach is inherently reactive and depends on end users to detect issues, which means vulnerabilities can be exploited for weeks or months before anyone notices. Manual per-laptop installation also introduces configuration drift, as each device may receive different updates at different times depending on user reports. Without a centralized patch management system and a known-good baseline, the organization loses visibility into the security posture of its fleet.
- ✗
Deploy all patches to every laptop immediately with no testing.
Why it's wrong here
Untested mass deployment of all patches to every laptop simultaneously is risky because a single problematic patch can break critical business applications or cause driver conflicts across the entire fleet at once. Security patches are not inherently safe; they can introduce new stability or compatibility issues. A lack of staged rollout means there is no opportunity to validate the patch on a small subset first, potentially leading to widespread operational downtime that outweighs the short-term security benefit.
- ✓
Use a phased rollout with a pilot group, then expand deployment after validation, while keeping a standard baseline configuration.
Why this is correct
A phased or ring-based rollout balances speed and stability. A pilot group catches compatibility issues early, and the baseline keeps endpoint settings consistent across the fleet. This approach reduces risk from vulnerabilities without creating unnecessary operational disruption.
- ✗
Wait for annual maintenance windows so all changes happen at once.
Why it's wrong here
Waiting for annual maintenance windows means known vulnerabilities remain unmitigated for up to a year, which is unacceptable for a fleet of 300 laptops and far outside the typical patch cadence. This approach treats patching as a static, once-a-year event rather than an ongoing risk management process, and it fails to account for zero-day exploits and emerging threats. Additionally, bundling all changes into a large annual batch increases the risk of deployment failures and makes troubleshooting more difficult.
Go deeper
Related to this question
Learn chapter
Firewall Types and Deployment
Key term
Risk mitigation
Risk mitigation is the process of reducing the likelihood or impact of a potential security threat to an acceptable level through specific controls and actions.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.