A security administrator must deploy a critical security patch across enterprise production application servers following standard change control and patch management practices. Place the following operational lifecycle steps in the correct sequential order from first to last.
- 1Validate the patch in an isolated sandbox environment to test for system instability or application compatibility issues.
- 2Submit a formal change request to the Change Advisory Board (CAB) detailing the patch impact, risk analysis, and emergency rollback procedure.
- 3Deploy the patch to a pilot/staging fleet to monitor performance and gather telemetry under representative operational workloads.
- 4Execute the enterprise-wide patch installation across all remaining production servers during an approved maintenance window.
- 5Perform an automated vulnerability compliance scan and update the official configuration baseline.
Answer
The correct operational sequence begins with non-production sandbox testing, followed by submitting a formal change request to the Change Advisory Board, deploying to a pilot/staging fleet, executing the full production deployment during a scheduled maintenance window, and finally auditing compliance to update the configuration baseline.
Structured patch and configuration management follows a strict procedural lifecycle: non-production sandbox testing, formal Change Advisory Board authorization, staged pilot deployment, enterprise production rollout, and final post-installation verification auditing.
Step-by-Step Solution
Key Concept
Standard Patch Management Lifecycle and Change Governance