ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your team manages a fleet of Linux web servers running in an IaaS cloud auto-scaling group that can add and remove instances at any time. A critical kernel vulnerability has been announced. To keep the fleet compliant with corporate baseline requirements while avoiding service downtime, which patch-management strategy should you implement first?

  • Create a new hardened machine image that contains the kernel patch and perform a rolling replacement of all instances in the auto-scaling group.

  • Rely on the cloud provider's host-level patching; no action is needed because the underlying hypervisor will be updated automatically.

  • Open an emergency maintenance window, SSH to every running instance, run the package manager to install the patch, and then reboot each server in sequence.

  • Temporarily raise the auto-scaling group's maximum size, run a remote patching script on the original instances, and then scale back down when finished.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot