A security engineer is assigned to work with the patch and vulnerability management group. The deployment of a new patch has been approved and needs to be applied.
The research is complete, and the security engineer has provided recommendations. Where should the patch be applied FIRST?
Correct Answer: C
The patch should be applied first to the lower environment, before being applied to the higher environments, such as the server, desktop, or production environment. The lower environment is the environment that is used for testing, development, or staging purposes, and that is isolated from the higher environments, which are used for operational, functional, or live purposes. The lower environment is the best place to apply the patch first, as it can help to verify the functionality, compatibility, and security of the patch, and to identify and resolve any issues or errors that may arise from the patch. Applying the patch to the lower environment first can help to minimize the risk and impact of the patch to the higher environments, and to ensure the quality and reliability of the patch . References: [CISSP CBK, Fifth Edition, Chapter 6, page 568]; [CISSP Practice Exam
- FREE 20 Questions and Answers, Question 16].