Question

Difficulty: EasyChange Management and Security Impacts

A system administrator needs to update an operational system to resolve a software vulnerability. Which of the following actions should the administrator take FIRST as part of the formal change management process to evaluate potential security impacts?

  1. Test the update in a staging environment to evaluate functionality and security side effects.Answer
  2. B
    Deploy the update directly into the live production environment during peak operating hours.
  3. C
    Bypass Change Advisory Board (CAB) approval to accelerate the patch deployment timeline.
  4. D
    Reconfigure perimeter firewall rules to block all traffic while applying the patch.

Answer

Test the update in a staging environment to evaluate functionality and security side effects.
Testing software updates in a non-production staging environment ensures that potential security flaws, instability, or system incompatibilities are identified and resolved before moving changes to live production systems.

Step-by-Step Solution

1
Identify the primary requirement in change control procedures.
Recognize that proposed system modifications must be evaluated for security impacts prior to production release.
Controlled testing prevents unexpected security gaps or operational failures.
2
Select the initial step of assessing impact.
Conducting testing in a non-production staging environment provides empirical data on stability and security.
Staging mirrors production without exposing live systems to operational risk.

Key Concept

Evaluating security impacts in change management staging environments
Estimated Time:45s
Rate this question