Question 135
Main Page
You identify unpatched systems due to business team resistance. What should you do?
A. Force system shutdown
B. Accept the risk without documentation
C. Work with risk owners to document exceptions and apply compensating controls
D. Revoke all user access
Answer: Work with risk owners to document exceptions and apply compensating controls
Business engagement and documented risk treatment are necessary when patching cannot be applied.