SY0-701 Security Operations Practice Question
A critical patch must be applied to a retail point-of-sale server. What is the best way to reduce business disruption?
⚠ Common exam trap
Many exam-takers choose Option A, thinking that applying a patch sooner reduces risk, but they overlook the immediate business disruption and the importance of change management processes that prioritize availability over speed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule the patch during an approved maintenance window.
Scheduling the patch during an approved maintenance window is the best practice to minimize business disruption because it allows the organization to plan for downtime during low-activity periods, coordinate with stakeholders, and ensure rollback procedures are in place. For a retail point-of-sale (POS) server, applying a critical patch outside of business hours prevents transaction interruptions and potential revenue loss, aligning with change management policies that prioritize availability and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch during the busiest business hours to make the change sooner.
Why it's wrong here
Applying a critical patch during peak retail hours directly interrupts transaction processing and customer-facing services, often requiring a reboot or application restart that causes downtime at the worst possible time. If the patch fails or introduces a regression, recovery efforts must compete with live sales traffic, amplifying business loss. A properly scheduled maintenance window minimizes user impact and provides a controlled environment for testing, monitoring, and rollback.
- ✓
Schedule the patch during an approved maintenance window.
Why this is correct
A maintenance window is the best choice because it lets the organization perform the update when user impact is expected to be lowest. This is a core change-control practice for systems that support business operations. It gives the team time to test, monitor, and recover if something goes wrong without affecting customers during peak use.
- ✗
Skip the patch and rely on hope that the issue will not be exploited.
Why it's wrong here
Skipping a critical patch exposes the point-of-sale system to a known, actively exploitable vulnerability, which is a direct violation of basic change and risk management principles. Retail environments handling cardholder data are obligated to maintain effective security controls, often under frameworks like PCI DSS, and documented patch management is a core requirement. Relying on hope leaves the organization defenseless against a foreseeable compromise, making the risk both unnecessary and unacceptable.
- ✗
Turn off all backups so the patch process runs faster.
Why it's wrong here
Disabling backups before a patch removes the only reliable safety net for restoring the system if the update causes data corruption, boot failure, or application incompatibility. The time saved by not running backups is negligible compared to the potential hours or days of downtime required to rebuild a compromised or broken POS system from scratch. Proper patching practice requires creating a verified backup beforehand so that quick rollback can restore normal retail operations if the change goes poorly.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Availability
Availability is the measure of how often a system or service is operational and accessible when needed, typically expressed as a percentage of uptime.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.