Soru

Zorluk: ZorPatch Management and Software Maintenance

A network administrator receives a critical zero-day vulnerability advisory affecting the operating system of two enterprise core switches configured as a high-availability active/standby pair. Applying the software patch requires a full reboot of the updated switch. To mitigate operational risk, preserve service uptime, and ensure rollback capability during this emergency maintenance, which of the following procedures represents the correct workflow for deploying the patch?

  1. Staging and validating the patch in an isolated lab environment, backing up the current running configurations, securing emergency Change Advisory Board (CAB) approval, applying the patch to the standby switch first, verifying standby health, failing over active traffic to the standby switch, and subsequently patching the former active switch.Cevap
  2. B
    Deploying the hotfix simultaneously to both active and standby switches during production hours without prior lab validation to eliminate the critical vulnerability window across the network as rapidly as possible.
  3. C
    Applying the software update directly to the primary active switch first without taking a baseline configuration backup, as active configuration state is automatically synchronized to the standby switch after reboot.
  4. D
    Downgrading both core switches to a legacy firmware version that lacks the vulnerable module feature to avoid executing patch management and change control protocols.

Cevap

The correct operational approach is to validate the patch in a lab environment, back up current configurations, obtain emergency change approval, patch the standby switch first, perform a controlled failover, and then patch the remaining switch.
Safe network software maintenance in high-availability environments requires a structured workflow: pre-test in a lab environment, create baseline configuration backups, obtain proper change management authorization, patch the standby device first, verify stability, execute a controlled failover, and patch the remaining device. This guarantees network uptime and provides clear rollback procedures at every step.

Adım Adım Çözüm

1
Pre-deployment staging and backup
Patch compatibility is verified in a non-production lab environment, and current operational configurations are safely backed up to allow rapid restoration if needed.
Prevents deploying untested firmware directly to production infrastructure and establishes a known-good restore baseline.
2
Change control and standby updating
Emergency CAB approval is secured, and the patch is applied to the standby switch while the active switch continues processing production traffic.
Protects production uptime by ensuring active network traffic is unaffected while updating the redundant node.
3
Validation, failover, and active updating
The upgraded standby switch is confirmed healthy, active traffic is manually failed over to it, and the former active switch is updated to achieve version parity.
Validates the stability of the newly patched OS in production with minimal disruption before completing the patch across both nodes.

Anahtar Kavram

High-Availability Patch Management & Controlled Rollout Sequences
Tahmini Süre:2m 0s
Bu soruyu puanla