Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

A help desk team manages 300 Windows laptops. A legacy accounting app sometimes fails after updates, so the company wants to reduce patch risk while still preventing long-term exposure. Which patching strategy is the best balance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a pilot group and phased rollout process before wider deployment.

A phased rollout with a pilot group is the most balanced approach. It allows the team to test new patches on a few systems that reflect the production environment before exposing the entire fleet to possible compatibility issues. That lowers operational risk while still ensuring the organization patches regularly, which is essential for reducing exposure to known vulnerabilities and maintaining a secure baseline. Why others are wrong: Option A is too labor-intensive and still lacks controlled validation. Option C accepts avoidable risk by deferring all updates indefinitely. Option D is reactive and leaves the fleet exposed until an incident occurs. The correct answer is the only one that preserves security and operational stability at the same time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply updates manually to each laptop as soon as they are released.

    Why it's wrong here

    Manually applying every update to 300 laptops on release day is operationally unscalable and introduces human error, such as missed devices or interrupted installations. It bypasses the change management cycle, allowing no compatibility testing against the legacy accounting application or line-of-business software before production impact. Furthermore, immediate deployment eliminates the chance to observe early warning signs from the vendor or community, so a bad patch could degrade hundreds of endpoints simultaneously.

  • Use a pilot group and phased rollout process before wider deployment.

    Why this is correct

    A pilot-to-broad rollout strategy lets the organization validate patches on a small set of representative devices before deploying them widely. That reduces the chance of a widespread compatibility problem while still keeping systems updated on a reasonable schedule. It is a practical balance between security, reliability, and operational risk.

  • Postpone all updates until the legacy accounting app is replaced.

    Why it's wrong here

    Deferring all patches until the legacy app is replaced leaves known, exploitable vulnerabilities unmitigated for an undefined period, creating a growing attack surface for ransomware and lateral movement. It also assumes the replacement will occur on a definite timeline, but few legacy migration projects are guaranteed, and the laptops may run out of vendor support long before that. This approach ignores compensating controls like network segmentation or endpoint hardening, and it places the organization in a reactive posture that is difficult to reverse.

  • Disable automatic updates permanently and patch only after a security incident.

    Why it's wrong here

    Patching only after a security incident treats remediation as forensic cleanup rather than preventive hardening, ensuring that every device remains vulnerable until breach confirmation. Permanently disabling Windows Update also means losing reliability patches, driver updates, and definition rollouts, which can create instability and expand the attack surface beyond just known CVEs. Empirically, detection-to-remediation times are long, and incident-driven patching is more expensive and slower than a scheduled, tested rollout.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.