Patch Management & Updates Flashcards
7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Patch Management & Updates flashcards as text
Which patching approach deploys updates to a small subset of production systems before wider rollout?
Answer: Canary deployment
Canary deployment rolls out patches to a small representative group first, allowing administrators to detect issues before affecting the entire environment.
What is the role of a patch management policy in an organization?
Answer: To establish rules, responsibilities, and timelines for applying patches consistently
A patch management policy sets the organizational framework—including who is responsible and how quickly patches must be applied—to ensure consistent and timely remediation.
After deploying a patch in a test environment with no issues, a technician pushes it to production and the application crashes. What should be done FIRST?
Answer: Execute the rollback plan to restore the previous state
Executing the pre-defined rollback plan restores systems to their pre-patch state quickly, minimizing downtime while the root cause is investigated.
Which tool category is MOST commonly used to automate enterprise-wide patch deployment?
Answer: Patch management platforms (e.g., WSUS, SCCM, Ansible)
Patch management platforms like WSUS, SCCM, or Ansible automate the scanning, approval, distribution, and verification of patches across large environments.
An end user refuses to allow a security patch because it requires a restart during business hours. What is the BEST response?
Answer: Schedule the patch and reboot during an approved off-hours maintenance window
Scheduling the patch during an off-hours maintenance window balances the user's operational needs with the security requirement to apply the patch promptly.
What is the difference between a hotfix and a service pack?
Answer: A hotfix addresses a specific urgent issue; a service pack is a cumulative collection of patches
Hotfixes target a single specific issue and are released quickly, while service packs bundle multiple cumulative updates into one installable package.
Which of the following is a KEY risk of delaying patch application beyond the defined SLA?
Answer: Extended window of exposure for known vulnerabilities
Every day a known vulnerability remains unpatched beyond the SLA increases the organization's exposure to exploitation by threat actors who use public vulnerability information.