Study. uk . com
  1. Home
  2. All questions
  3. Question 67

CISSP study material · question 67 of 500

An enterprise marks a patch as complete once its deployment console reports the package was pushed to the target group. An auditor later finds several of those servers still running the vulnerable version. Which activity closes the patch management cycle?

  1. Verifying on each affected asset itself that the patch was actually applied
  2. Ranking the vulnerability by severity before the deployment window opens
  3. Acquiring the patch from the vendor through a channel whose integrity is checked
  4. Recording the vendor advisory reference against the approved change ticket
Show the answer

Answer: A. Verifying on each affected asset itself that the patch was actually applied

The patching loop closes only when someone confirms the fix landed on the box; finding, prioritising and obtaining the patch are earlier steps in the same maintenance cycle.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 > Abstract

Challenge yourself on this topic → Study as cards