Soru

Zorluk: OrtaPatch and Configuration Management

A security operations team is responding to a newly disclosed critical remote code execution vulnerability impacting enterprise database servers. To ensure operational stability while mitigating risk, what is the correct chronological sequence of steps the team should perform during this emergency patch deployment workflow?

  1. 1Assess vendor patch notes, evaluate system dependencies, and deploy the update to a non-production staging environment for regression testing.
  2. 2Submit an emergency Change Advisory Board (CAB) request including a detailed risk analysis and documented rollback plan.
  3. 3Execute the patch deployment across production database hosts during an authorized maintenance window.
  4. 4Perform credentialed vulnerability scanning and audit configuration baselines to confirm remediation and detect any settings drift.

Cevap

The correct sequence begins with evaluating and testing the patch in a non-production staging environment, followed by submitting an emergency change request with a rollback plan to the Change Advisory Board (CAB). Once authorized, the patch is deployed to production database hosts during an approved window, and finally, credentialed scanning and baseline auditing are performed to confirm success.
The correct operational sequence follows structured patch and change management governance. Testing in a non-production environment occurs first to verify stability. Next, emergency CAB approval ensures stakeholder authorization and rollback readiness. The patch is then deployed to production, and post-deployment credentialed scanning verifies successful remediation without baseline drift.

Adım Adım Çözüm

1
Stage and test the emergency patch in a non-production environment.
Identified potential application incompatibility and confirmed system stability before touching live systems.
Applying untested patches directly to production risks outage or service failure.
2
Obtain CAB approval with documented rollback procedures.
Emergency change request is authorized by stakeholders with an agreed contingency plan.
Change management policy mandates authorized approval and risk governance even during emergency windows.
3
Deploy the patch to production hosts during the maintenance window.
Vulnerability mitigation is applied across production target machines.
Execution must occur after validation and authorization within controlled timeframes.
4
Validate deployment via credentialed scanning and configuration baseline checks.
Confirmed successful vulnerability remediation and verified configuration compliance without drift.
Operational verification ensures the flaw is eliminated and no system settings were unintentionally altered.

Anahtar Kavram

Standard Emergency Patch Management Lifecycle and Governance Workflow
Tahmini Süre:1m 30s
Bu soruyu puanla