Study. uk . com
  1. Home
  2. All questions
  3. Question 424

CISSP study material · question 424 of 500

After a patch deployment, an audit finds that several hardened settings have reverted to vendor defaults. Which risk does NIST SP 800-40 Rev. 4 identify here?

  1. The patch was not validated and must have been tampered with in transit.
  2. The patch failed to take effect and the settings are from the previous version.
  3. The rollback procedure ran automatically and restored an older baseline.
  4. Installing a patch may alter or add security configuration settings, creating a new problem while fixing the original one.
Show the answer

Answer: D. Installing a patch may alter or add security configuration settings, creating a new problem while fixing the original one.

Patch installation can alter existing security settings or add new ones, and those side effects can create a fresh security problem while closing the original.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 2.3.2 Deploy the Patch

Challenge yourself on this topic → Study as cards