← All CSA Flashcard Decks

Patch Management & Updates Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Patch Management & Updates flashcards as text
  1. Which compliance framework requires organizations to protect systems by applying security patches in a timely manner as part of its requirements?

    Answer: Both PCI DSS and other frameworks such as HIPAA and NIST SP 800-40

    Multiple compliance frameworks including PCI DSS (Requirement 6), HIPAA, and NIST SP 800-40 explicitly require timely patch management as part of risk management.

  2. What is a 'compensating control' in the context of patch management?

    Answer: An alternative security measure applied when a patch cannot be deployed immediately

    A compensating control is a temporary security measure—such as a firewall rule or IPS signature—that reduces risk when the actual patch cannot be applied right away.

  3. During a patch audit, an auditor finds that 15% of endpoints are still running an unpatched version 90 days after the patch's release. What does this MOST likely indicate?

    Answer: There is a gap in patch deployment coverage or enforcement that needs remediation

    A 15% non-compliance rate after 90 days signals a coverage or enforcement failure in the patch management process that should be investigated and corrected.

  4. Which of the following is a BENEFIT of automating patch deployment over manual patching?

    Answer: Automation reduces human error and accelerates consistent remediation across large environments

    Automated patch deployment reduces the risk of human error and enables faster, more consistent application of updates across thousands of endpoints simultaneously.

  5. A technician applies a patch that fixes a vulnerability but inadvertently breaks single sign-on (SSO) for 200 users. What phase of patch management was INADEQUATE?

    Answer: Pre-deployment testing in a representative staging environment

    Had SSO scenarios been tested in a staging environment that mirrored production, the compatibility issue would have been caught before impacting users.

  6. What is the purpose of a 'patch exception' process?

    Answer: To formally document, justify, and mitigate risks when a patch cannot be applied within policy timelines

    A patch exception process ensures deviations from policy are formally tracked, risk-justified, and accompanied by compensating controls rather than informally ignored.

  7. Which of the following BEST describes the relationship between vulnerability management and patch management?

    Answer: Vulnerability management identifies and prioritizes risks; patch management is one key remediation action

    Vulnerability management encompasses the full lifecycle of identifying, classifying, and remediating risks, while patch management is the specific process of applying vendor-released fixes as one remediation method.