QuestionQ1037

Information Security Program

What should be the FIRST action in patch-management procedures upon receiving an emergency security patch?

  • A Validate the authenticity of the patch.
  • B Conduct comprehensive testing of the patch.
  • C Schedule patching based on the criticality.
  • D Install the patch immediately to eliminate the vulnerability.
Explanation

An emergency security patch should first have its authenticity validated, such as by confirming its trusted vendor source and integrity/signature. This prevents a counterfeit or modified patch from introducing compromise into the environment.

Community Discussion

No comments yet. Be the first to start the discussion!