A security administrator needs to apply a critical security update to enterprise web servers. What is the correct sequence of steps the administrator should follow to complete the patch management workflow?
- 1Identify and acquire the security patch from a verified vendor source.
- 2Validate and test the security patch in a non-production staging environment.
- 3Submit a change request for review and approval by the Change Advisory Board (CAB).
- 4Deploy the patch to production servers during an authorized maintenance window.
Answer
The correct sequence for the patch management process is: 1) Identify and acquire the security patch, 2) Validate and test the patch in a non-production staging environment, 3) Submit a change request for approval by the Change Advisory Board, and 4) Deploy the patch to production servers.
The standard enterprise patch management lifecycle progresses logically from patch discovery and acquisition, to non-production staging validation, followed by formal governance approval from the Change Advisory Board, and concluding with scheduled deployment to production systems.
Step-by-Step Solution
Key Concept
Standard Enterprise Patch Management Lifecycle