CompTIA CASP+ (CAS-004) — Question 306

A hospital has fallen behind with patching known vulnerabilities due to concerns that patches may cause disruptions in the availability of data and impact patient care. The hospital does not have a tracking solution in place to audit whether systems have been updated or to track the length of time between notification of the weakness and patch completion. Since tracking is not in place, the hospital lacks accountability with regard to who is responsible for these activities and the timeline of patching efforts. Which of the following should the hospital do first to mitigate this risk?

Answer options

Correct answer: C

Explanation

The correct answer is C, as purchasing a ticketing system will provide the necessary tracking and auditing capabilities for patch management, ensuring accountability. Options A and B, while beneficial, do not directly address the immediate need for tracking updates. Option D is important but does not establish a system for monitoring patching efforts. Option E focuses on education but does not solve the tracking issue.