A patch management audit reveals that 15% of Windows workstations have not received the most recent security patches in 90 days. The primary reason is that these machines are used for 24/7 operations and cannot be rebooted. Which approach best balances security and operational continuity?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a pragmatic approach for operational systems combines scheduled low-impact patching, compensating controls that reduce exploitability of unpatched vulnerabilities, and formal risk acceptance documentation — meeting both operational and security governance requirements. A is wrong because permanent exemption creates an unmanaged risk that grows over time.
Full explanation below image
Full Explanation
B is correct because a pragmatic approach for operational systems combines scheduled low-impact patching, compensating controls that reduce exploitability of unpatched vulnerabilities, and formal risk acceptance documentation — meeting both operational and security governance requirements. A is wrong because permanent exemption creates an unmanaged risk that grows over time. C is wrong because forced reboots without planning may cause significant business disruption or data loss in 24/7 operations. D is wrong because removing the patch agent suppresses visibility, worsens security posture, and is a compliance violation.