SY0-701 Security Architecture Practice Question
A help desk team manages 300 Windows laptops. A legacy accounting app sometimes fails after updates, so the company wants to reduce patch risk while still preventing long-term exposure. Which patching strategy is the best balance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a pilot group and phased rollout process before wider deployment.
A phased rollout with a pilot group is the most balanced approach. It allows the team to test new patches on a few systems that reflect the production environment before exposing the entire fleet to possible compatibility issues. That lowers operational risk while still ensuring the organization patches regularly, which is essential for reducing exposure to known vulnerabilities and maintaining a secure baseline. Why others are wrong: Option A is too labor-intensive and still lacks controlled validation. Option C accepts avoidable risk by deferring all updates indefinitely. Option D is reactive and leaves the fleet exposed until an incident occurs. The correct answer is the only one that preserves security and operational stability at the same time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply updates manually to each laptop as soon as they are released.
Why it's wrong here
Manually applying every update to 300 laptops on release day is operationally unscalable and introduces human error, such as missed devices or interrupted installations. It bypasses the change management cycle, allowing no compatibility testing against the legacy accounting application or line-of-business software before production impact. Furthermore, immediate deployment eliminates the chance to observe early warning signs from the vendor or community, so a bad patch could degrade hundreds of endpoints simultaneously.
- ✓
Use a pilot group and phased rollout process before wider deployment.
Why this is correct
A pilot-to-broad rollout strategy lets the organization validate patches on a small set of representative devices before deploying them widely. That reduces the chance of a widespread compatibility problem while still keeping systems updated on a reasonable schedule. It is a practical balance between security, reliability, and operational risk.
- ✗
Postpone all updates until the legacy accounting app is replaced.
Why it's wrong here
Deferring all patches until the legacy app is replaced leaves known, exploitable vulnerabilities unmitigated for an undefined period, creating a growing attack surface for ransomware and lateral movement. It also assumes the replacement will occur on a definite timeline, but few legacy migration projects are guaranteed, and the laptops may run out of vendor support long before that. This approach ignores compensating controls like network segmentation or endpoint hardening, and it places the organization in a reactive posture that is difficult to reverse.
- ✗
Disable automatic updates permanently and patch only after a security incident.
Why it's wrong here
Patching only after a security incident treats remediation as forensic cleanup rather than preventive hardening, ensuring that every device remains vulnerable until breach confirmation. Permanently disabling Windows Update also means losing reliability patches, driver updates, and definition rollouts, which can create instability and expand the attack surface beyond just known CVEs. Empirically, detection-to-remediation times are long, and incident-driven patching is more expensive and slower than a scheduled, tested rollout.
Go deeper
Related to this question
Learn chapter
Cloud Security Fundamentals
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.