Soru

Zorluk: OrtaPatch and Configuration Management

A security operations team is establishing a standardized patch management workflow to ensure system security while minimizing operational disruption across the enterprise. Place the steps of the enterprise patch management lifecycle in the correct procedural sequence from initial identification to post-implementation audit.

  1. 1Analyze vulnerability intelligence feeds and prioritize missing vendor updates based on asset criticality.
  2. 2Apply and evaluate the updates within a non-production staging environment to verify system stability and application compatibility.
  3. 3Submit a formal change request to the Change Advisory Board (CAB) including deployment risk assessments and rollback plans.
  4. 4Execute a phased rollout of the updates across production systems during authorized maintenance windows.
  5. 5Perform automated security baseline auditing and vulnerability scanning to confirm successful remediation and drift prevention.

Cevap

The correct procedural sequence for the patch management lifecycle is: (1) Analyze vulnerability intelligence feeds and prioritize missing vendor updates based on asset criticality; (2) Apply and evaluate the updates within a non-production staging environment to verify system stability and application compatibility; (3) Submit a formal change request to the Change Advisory Board (CAB) including deployment risk assessments and rollback plans; (4) Execute a phased rollout of the updates across production systems during authorized maintenance windows; and (5) Perform automated security baseline auditing and vulnerability scanning to confirm successful remediation and drift prevention.
The standard patch management lifecycle follows a structured progression: vulnerability identification and prioritization must occur first, followed by pre-deployment testing in staging to ensure stability. Once validated, formal approval from the Change Advisory Board (CAB) is sought with a documented rollback plan. Production deployment is then executed in a phased manner during scheduled maintenance windows, ending with post-patch auditing and baseline verification to confirm vulnerability remediation.

Adım Adım Çözüm

1
Identify and prioritize patch requirements
Assets requiring updates are cataloged according to vulnerability severity and business impact.
Security operations must first assess incoming threats and asset inventory to prioritize remediation efforts effectively.
2
Conduct staging and compatibility testing
Updates are tested in an environment duplicating production configuration without risking live operations.
Pre-deployment testing identifies application dependencies, performance impacts, or instabilities caused by the patch.
3
Obtain Change Advisory Board approval
Change request is reviewed, scheduled, and authorized with explicit rollback procedures established.
Enterprise governance requires documented change authorization to minimize unannounced maintenance outages.
4
Deploy to production systems
Patches are distributed to live environments using staged, canary, or phased maintenance windows.
Phased execution limits blast radius and ensures controlled delivery across operational infrastructure.
5
Validate posture and configuration baselines
Vulnerability scans confirm patch application and ensure configuration baselines have not drifted.
Verification confirms patch success and prevents posture regression or configuration drift.

Anahtar Kavram

Enterprise Patch Management Lifecycle
Bu soruyu puanla