- Home
- All questions
- Question 424
CISSP study material · question 424 of 500
After a patch deployment, an audit finds that several hardened settings have reverted to vendor defaults. Which risk does NIST SP 800-40 Rev. 4 identify here?
Show the answer
Answer: D. Installing a patch may alter or add security configuration settings, creating a new problem while fixing the original one.
Patch installation can alter existing security settings or add new ones, and those side effects can create a fresh security problem while closing the original.
Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 2.3.2 Deploy the Patch