An enterprise security team becomes aware of a newly disclosed critical vulnerability in a widely deployed operating system. According to sound configuration-management practice, how should the team treat the organization's approved configuration baselines in response to this discovery?
Defer any baseline updates until the next scheduled annual baseline review, regardless of the vulnerability's severity.
Leave the baselines unchanged and simply add the issue to a separate vulnerability-exception list indefinitely.
Evaluate whether the vulnerability affects the organization's systems, test the remediation in a staging environment, obtain change-management approval, and then update the baselines.
Update the baselines immediately to include the vendor's patch, even before confirming whether any in-scope systems are affected.
The baselines should not be changed the moment a vulnerability is announced. A configuration baseline is a formally approved, secure state that can be altered only through established change-control procedures. The correct approach is to confirm whether the vulnerability applies to the organization's assets, test any remediation (such as vendor patches) in a non-production environment, obtain formal change-management approval, and then update the baseline. Updating immediately, without assessment or testing, risks operational disruption, incompatibilities, or the introduction of new weaknesses. Waiting until an annual review or ignoring the baseline changes altogether also leaves the environment at increased risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a configuration baseline in security?
Open an interactive chat with Bash
Why is testing patches in a non-production environment necessary?
Open an interactive chat with Bash
What is change-management approval, and why is it important?
Open an interactive chat with Bash
ISC2 CISSP
Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .