Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security auditor discovers that several critical servers in a data center are running operating systems and applications with known vulnerabilities for which patches have been available for months. This oversight significantly increases the risk of exploitation. Which endpoint security best practice has been neglected in this scenario?

  1. AData Loss Prevention (DLP)
  2. BApplication Whitelisting
  3. CPatch Management
  4. DMobile Device Management (MDM)
Show answer & explanation

Correct answer: C. Patch Management

Patch Management is the process of acquiring, testing, and applying code changes (patches) to software and operating systems to fix bugs, improve performance, and, critically, address security vulnerabilities. Neglecting this process leaves systems exposed to known exploits.

Why the other options are wrong

  • A. DLP prevents data exfiltration, not vulnerability patching.
  • B. Application Whitelisting controls what software can run, not the security updates for existing software.
  • D. MDM manages mobile devices, not server patching.

Patch Management

The systematic process of identifying, acquiring, testing, and applying updates (patches) to software, firmware, and operating systems to fix bugs, improve functionality, and resolve security vulnerabilities.

  • Crucial for reducing the attack surface by closing known security gaps.
  • Requires a structured approach to avoid system instability.
  • Includes regular scanning for missing patches and scheduled deployment.

Memory trick: Patch management is like giving your systems their flu shots to prevent infection.

More Endpoint Security questions