ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization's ERP vendor has released an out-of-band patch that corrects a critical privilege-escalation flaw currently being exploited in the wild. As the patch-management lead, what is the most appropriate next step to take before deploying the update to production systems, in line with secure patch-management best practices?
Postpone deployment until the next quarterly release cycle to maintain the established update schedule and avoid unplanned downtime.
Disable the vulnerable ERP module permanently and rely on manual workarounds instead of installing the vendor's patch.
Perform comprehensive testing of the patch in a representative staging environment to verify compatibility and security before scheduling a controlled rollout.
Apply the patch immediately to all production servers, bypassing the normal change-management process to reduce exposure time.
Secure patch-management processes require validating vendor fixes in a non-production environment that mirrors the target systems. Testing in a staging environment confirms that the patch installs cleanly, does not introduce regressions, and does not break business workflows. Skipping testing or change-control can cause outages; indefinitely postponing or relying on work-arounds leaves the organization exposed to the active threat. Therefore, testing the patch in a representative environment and then planning a controlled rollout is the correct approach.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is testing patches in a staging environment essential?
Open an interactive chat with Bash
What is privilege escalation, and why is it critical to address?
Open an interactive chat with Bash
What are secure patch-management best practices?
Open an interactive chat with Bash
What is a staging environment and why is it important in patch management?
Open an interactive chat with Bash
What is privilege escalation and why does it need immediate remediation?
Open an interactive chat with Bash
What are best practices for a controlled patch rollout?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)