Study. uk . com
  1. Home
  2. All questions
  3. Question 422

CISSP study material · question 422 of 500

A security lead argues patch testing is a security control. How does NIST SP 800-40 Rev. 4 characterise its purpose?

  1. It reduces cybersecurity risk by confirming the vulnerability is actually closed.
  2. It establishes the patch's authenticity where a signature is unavailable.
  3. It reduces operational risk by finding problems the patch itself would cause before it reaches production.
  4. It satisfies a legal requirement for change validation.
Show the answer

Answer: C. It reduces operational risk by finding problems the patch itself would cause before it reaches production.

SP 800-40 says testing a patch before deployment is intended to reduce operational risk by identifying problems with the patch before placing it into production.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 2.3.1 Prepare to Deploy the Patch

Challenge yourself on this topic → Study as cards