A security operations team is responding to a newly disclosed critical remote code execution vulnerability impacting enterprise database servers. To ensure operational stability while mitigating risk, what is the correct chronological sequence of steps the team should perform during this emergency patch deployment workflow?
- 1Assess vendor patch notes, evaluate system dependencies, and deploy the update to a non-production staging environment for regression testing.
- 2Submit an emergency Change Advisory Board (CAB) request including a detailed risk analysis and documented rollback plan.
- 3Execute the patch deployment across production database hosts during an authorized maintenance window.
- 4Perform credentialed vulnerability scanning and audit configuration baselines to confirm remediation and detect any settings drift.
Answer
The correct sequence begins with evaluating and testing the patch in a non-production staging environment, followed by submitting an emergency change request with a rollback plan to the Change Advisory Board (CAB). Once authorized, the patch is deployed to production database hosts during an approved window, and finally, credentialed scanning and baseline auditing are performed to confirm success.
The correct operational sequence follows structured patch and change management governance. Testing in a non-production environment occurs first to verify stability. Next, emergency CAB approval ensures stakeholder authorization and rollback readiness. The patch is then deployed to production, and post-deployment credentialed scanning verifies successful remediation without baseline drift.
Step-by-Step Solution
Key Concept
Standard Emergency Patch Management Lifecycle and Governance Workflow
Estimated Time:1m 30s