Question 1 of 30
The investigation demonstrates that a critical vulnerability has been identified in a widely used third-party application deployed across multiple business-critical servers. While a patch is available, the vendor\'s release notes indicate potential compatibility issues with certain legacy operating systems that are still in use. The security team is under pressure to remediate immediately, but the IT operations team is concerned about the potential for widespread system outages if the patch causes instability. What is the most appropriate course of action for the security team to take?
Conduct a phased rollout of the patch, starting with non-critical systems and a dedicated testing environment, while simultaneously developing temporary mitigation strategies for critical systems until full compatibility is confirmed.
Immediately deploy the patch to all affected servers to eliminate the vulnerability as quickly as possible, accepting the risk of potential downtime.
Postpone all patching activities until the IT operations team can fully upgrade all legacy operating systems, which is estimated to take several months.
Prioritize patching only those servers that are easily accessible and have the latest operating systems, leaving other systems vulnerable for the time being.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free