A senior network operations engineer must deploy a critical vendor-issued firmware security patch to an active/passive high-availability pair of core enterprise switches. The patch addresses an unauthenticated remote code execution vulnerability but requires a complete system reboot of each appliance. To maintain zero unmanaged downtime, protect configuration state, and adhere to strict enterprise patch management procedures, which of the following operational workflows should the engineer execute?
- Submit a change request to the Change Advisory Board (CAB), perform configuration and baseline state backups, validate the firmware update in a non-production staging environment, schedule a maintenance window, execute a rolling upgrade beginning with the standby switch, and verify redundancy prior to updating the active switch.Answer
- BImmediately push the firmware update directly to the primary active switch during peak operational hours to eliminate security exposure, skipping pre-deployment lab testing and taking configuration backups only after the switch successfully reboots.
- CPerform a complete system image restore using the previous week's incremental backup directly onto the primary switch before starting the live firmware installation file transfer.
- DReconfigure the Virtual Router Redundancy Protocol (VRRP) master node to point directly to an external public IP address rather than the local virtual gateway IP (VIP) to maintain routing throughout the reboot sequence.
Answer
The correct workflow requires securing Change Advisory Board authorization, backing up the current baseline configuration, testing the patch in a non-production lab environment, scheduling an approved maintenance window, and performing a rolling upgrade starting with the standby switch before updating the active node.
The standard patch management lifecycle for high-availability enterprise environments requires change management authorization, configuration state backup, staging environment verification, scheduled maintenance windows, and a staged rolling update starting with non-active nodes to guarantee continuous availability and rapid recovery capabilities.
Step-by-Step Solution
Key Concept
Enterprise Patch Management Lifecycle and High-Availability Maintenance
Estimated Time:2m 0s