mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: A company runs its production workloads on a…
A company runs its production workloads on a cloud platform. The security team wants to ensure that all compute instances are patched within 30 days of a patch release. Which of the following is the BEST approach to enforce this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an automated patch management tool that deploys patches to all instances within 30 days
An automated patch management tool ensures that patches are deployed to all instances within the specified timeline, enabling enforcement of the 30-day requirement. Option B is wrong because vulnerability scanning only identifies unpatched instances but does not apply the patches. Option C is wrong because a change management process requiring approval can introduce delays that may prevent patching within 30 days. Option D is wrong because a manual patching policy lacks enforcement and may result in missed deadlines due to human error or negligence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use an automated patch management tool that deploys patches to all instances within 30 days
Why this is correct
Automation enforces timeline.
- ✗
Configure vulnerability scanning to identify unpatched instances and notify administrators
Why it's wrong here
Identification but no enforcement.
- ✗
Create a change management process that requires approval for all patches
Why it's wrong here
Approval may delay patching beyond 30 days.
- ✗
Implement a manual patching policy and require each team to submit a patch report monthly
Why it's wrong here
No enforcement of timeline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.