Question

Difficulty: MediumPatch and Configuration Management

A security analyst managing legacy workstation endpoints in a healthcare facility needs to remediate a critical operating system vulnerability. Vendor patches frequently reset customized local security policies back to default settings, exposing the devices to unauthorized access. Which of the following approaches best maintains system security baselines while ensuring timely vulnerability remediation?

  1. Validate vendor updates in a mirrored staging environment, document configuration baseline variations, and deploy updates via standard change management procedures.Answer
  2. B
    Deploy network perimeter firewall blocks on affected ports as a permanent substitute for installing the operating system software patches.
  3. C
    Reclassify patch management procedures as detective security controls so automated system logging can restore security baselines.
  4. D
    Immediately push vendor patches to all live production endpoints during operational hours to minimize the attack window.

Answer

Validate vendor updates in a mirrored staging environment, document configuration baseline variations, and deploy updates via standard change management procedures.
Testing patches within a mirrored staging environment ensures that any configuration baseline overrides caused by vendor updates are identified and corrected prior to production deployment.

Step-by-Step Solution

1
Analyze the security and operational risk
Identified that applying vendor patches directly causes configuration drift by overwriting custom security hardening settings.
Production environments require both vulnerability mitigation and strict adherence to security configuration baselines.
2
Evaluate remediation strategies
Staging environments allow security teams to observe patch behavior and baseline changes without impacting live systems.
Staging validation identifies baseline regressions early so post-patch configuration scripts can be prepared prior to live deployment.

Key Concept

Patch and Configuration Baseline Auditing in Change Management
Estimated Time:1m 30s
Rate this question