Study. uk . com
  1. Home
  2. All questions
  3. Question 427

CISSP study material · question 427 of 500

An organisation records a patch as deployed once the distribution tool reports success. Which further step does NIST SP 800-40 Rev. 4 identify, and what does it need at scale?

  1. Verification that the patch installed and took effect, which generally needs automation at scale.
  2. Recertification of the asset by the authorising official.
  3. Re-validation of the patch's signature, which must be done by hand.
  4. Re-prioritisation of the remaining patches, which must be manual.
Show the answer

Answer: A. Verification that the patch installed and took effect, which generally needs automation at scale.

Verification is its own step: confirming the patch installed and took effect. At any scale automated means are generally needed to do it.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > 2.3.3 Verify Deployment

Challenge yourself on this topic → Study as cards