CompTIA Cloud+ (CV0-004)OperationsHard

A cloud security engineer is tasked with ensuring that all cloud resources are running the latest security patches. The organization uses a hybrid cloud environment with a mix of Linux and Windows virtual machines, containers, and serverless functions. What is the MOST efficient lifecycle management approach for consistently applying security patches across this diverse environment?

  1. ARelying on the cloud provider's default patching for all services.
  2. BImplementing a centralized patch management solution integrated with CI/CD pipelines.
  3. CManual patching of each resource type on a monthly schedule.
  4. DDeveloping custom scripts for each resource type and running them on demand.
Show answer & explanation

Correct answer: B. Implementing a centralized patch management solution integrated with CI/CD pipelines.

A centralized patch management solution integrated with CI/CD pipelines provides automation and consistency across diverse environments. This allows for testing patches before deployment and ensures that new deployments are always patched, which is crucial for efficiency and security in a hybrid cloud.

Why the other options are wrong

  • A. Cloud provider default patching often covers only the underlying infrastructure, not guest OS or applications, and may not meet specific organizational policies.
  • C. Manual patching is inefficient, error-prone, and unsustainable for diverse, large-scale environments.
  • D. Custom scripts can be complex to maintain and lack a centralized view or automated deployment for all resource types.

Patch Management

The process of identifying, acquiring, testing, and applying software patches (updates, bug fixes, security fixes) to systems.

  • Crucial for security and stability.
  • Can be complex in diverse environments.
  • Automation and centralized tools improve efficiency.

Memory trick: Centralized CI/CD: The 'Patch' to automate and secure diverse clouds.

More Operations questions