A company discovers a critical vulnerability in a widely used software application. The vendor has released a patch, but the company's patch management policy requires testing before deployment. What is the best course of action?
Trap 1: Wait for the next scheduled maintenance window to apply the patch
Delaying patching for critical vulnerabilities increases risk of exploitation.
Trap 2: Deploy the patch immediately without testing to all systems
Immediate deployment to all systems may cause instability; a staged approach is better.
Trap 3: Test the patch in a staging environment and then deploy to…
Normal testing is appropriate for non-critical patches, but critical vulnerabilities may require expedited testing.
- A
Apply the patch using emergency change control to critical systems first, then test and deploy to others
Correct. Emergency patching prioritizes critical systems with expedited testing.
- B
Wait for the next scheduled maintenance window to apply the patch
Why it fails: Delaying patching for critical vulnerabilities increases risk of exploitation.
- C
Deploy the patch immediately without testing to all systems
Why it fails: Immediate deployment to all systems may cause instability; a staged approach is better.
- D
Test the patch in a staging environment and then deploy to production
Why it fails: Normal testing is appropriate for non-critical patches, but critical vulnerabilities may require expedited testing.