Question

Difficulty: MediumPatch Management and Software Maintenance

An enterprise network operations team needs to update the firmware across core network infrastructure following a vendor security disclosure. Place the standard operational steps of the patch management lifecycle in the correct order from first to last.

  1. 1Evaluate security advisories and identify all affected network hardware and software inventory.
  2. 2Install and test the patch in an isolated lab environment to verify stability and baseline compatibility.
  3. 3Submit a formal change request to the Change Advisory Board (CAB) and schedule an approved maintenance window.
  4. 4Perform running configuration backups and system image snapshots on all target network devices.
  5. 5Deploy the update during the maintenance window and audit system logs and network performance post-installation.

Answer

The correct operational sequence is: 1) Evaluate security advisories and inventory, 2) Test the patch in an isolated lab environment, 3) Submit a change request to the CAB and schedule a maintenance window, 4) Perform device configuration backups, and 5) Deploy during the maintenance window and audit performance post-installation.
The standard patch management process follows a logical lifecycle designed to minimize operational risk: vulnerability discovery and asset inventory, sandbox lab testing, formal Change Advisory Board (CAB) approval with scheduled maintenance windows, pre-deployment device configuration backups, and production deployment paired with post-patch auditing.

Step-by-Step Solution

1
Vulnerability Assessment and Discovery
Scope of affected devices and priority level are determined.
Administrators must discover which network assets are affected before taking operational action.
2
Lab Staging and Validation
Patch side effects are observed without risking production infrastructure.
Sandbox testing provides empirical performance metrics and validates rollback procedures.
3
Change Management Approval
The Change Advisory Board approves the deployment schedule.
Organizational governance requires authorized authorization and scheduled downtime notification.
4
Pre-Patch Baseline Backup
Device state and configuration files are archived safely.
Backups ensure immediate rollback capability if installation issues arise.
5
Production Deployment and Post-Audit
Software updates are applied and operational integrity is verified.
Completes the patch lifecycle while confirming normal network operations have resumed.

Key Concept

Patch Management Lifecycle Operations
Estimated Time:1m 30s
Rate this question