Ref URL: https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=901613
Ref Text:
Audit and Assessment
Systematic audit and assessment is critical to gauge the success and extent of patch
management efforts. After patch deployment, organizations should verify that they have
fixed or mitigated vulnerabilities as intended. They can accomplish this by reviewing
patch logs to verify whether the recommended patchers were installed properly,
conducting follow-up scans, and conducting penetration tests to make sure their systems
aren’t vulnerable to the exploit code the patch is designed to thwart.
They say "The success of a patch management process" Audit and assessment after the patch is deployed makes sense. But they are talking about the patch management process here... not after deploying the patch. I am thinking about maybe "A"
D. Auditing and assessment........if the question had used the word "ensure" instead of "determine" in that case i would have picked answer A. Change Management. Since the question is asking for "the BEST way to determine the success" instead of "the BEST way to ensure the success", the correct answer is therefore D. Auditing and assessment.
This question talks about the success of a process. It doesn't matter what the process is, I think "patching" is there to throw you off. Audit is really the best way to see if your process was successful or not.
Also here it talks abut audit, nothing about change management:
https://purplesec.us/learn/vulnerability-management-metrics/
D. Auditing and assessment is the best way to determine the success of a patch management process. Auditing involves regularly reviewing the patch management process to ensure that it is being implemented correctly and that all necessary patches are being applied. Assessment involves evaluating the effectiveness of the patch management process in reducing vulnerabilities and mitigating risks. Together, auditing and assessment provide a comprehensive view of the patch management process and allow for identification of areas for improvement.
From the CISSP Official Study Guide - 'Verifying that patches are deployed: After deploying patches, administrators regularly test and audit systems to unsure they are patched. Many deployment tools include the agility to audit systems. Additionally, many vulnerabilities assessment tools include the ability to check systems to ensure that they have the appropriate patches.'
Struggling between A and D.
Part of the Change management is to test, and document the change once it is completed.
Auditing and Assessment also can be the answer, for example security team uses Nessus scanner to make sure (assessing) servers do not have vulnerabilities.
I vote for D:
Change management is vital to every stage of the patch management process. As with all system modifications, patches and updates must be performed and tracked through the change management system. It is highly unlikely that an enterprise-scale patch management program can be successful without proper integration with the change management system and organization.
!
ref: https://www.alvaka.net/why-are-patch-management-and-change-management-important/
patch management are usually part of Enterprise Change Management.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf
"administrative activities occurring throughout the software vulnerability
management life cycle, such as updating documentation, audit logging, and generating actionable insights and reports as part of enterprise change management. Having robust change management policies and processes in place is a fundamental part of software vulnerability management"
It should be A, which it should be approved by management and tested by change management, and then leads to successful patch
upvoted 5 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
gautamzone
Highly Voted 2 years, 1 month agojackdryan
1 year, 6 months agofranbarpro
2 years, 1 month agoVino22
Highly Voted 2 years, 1 month agoSoleandheel
Most Recent 11 months, 2 weeks agoarron2023
1 year agoHughJassole
1 year, 5 months agoDee83
1 year, 10 months agoRVoigt
1 year, 10 months agoevenkeel
1 year, 10 months agooudmaster
1 year, 11 months agooudmaster
1 year, 11 months agoDracoL
2 years, 1 month agothomass
2 years, 1 month ago