QUALYS PATCH MANAGEMENT (PM);(
80%) CERTIFICATION SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◍ Steps in Patch Management.
Answer: 1. Inventory systems and configuration2. Identify new risks,
vulnerabilities3. Identify new patches4. Weigh patching risks5. Schedule
patch acquisition6. Verify patch integrity7. Test patches before deployment
(Regression testing: to ensure that previously developed and tested software
still functions properly after a patch.)8. Deploy the patches9.
Repeat•Automate patching activities, patch management tools•Lock down
patch procedures
◍ Technological Infrastructure Acquisition Plan.
Answer: •Produce a plan for the acquisition, implementation and
maintenance of the technological infrastructure that meets established
business functional and technical requirements and is in accord with the
organization's technology direction.
◍ •HP: 44% of breaches attributed to.
Answer: patched vulnerabilities over 2 years old
◍ What windows tool helps with auditing.
Answer: MSCCM
◍ Patch Planning.
Answer: Verify that patch is compatible with your system
◍ Change Standards and Procedures.
Answer: Set up formal change management procedures to handle in a
standardized manner all requests (including maintenance and patches) for
changes to applications, procedures, processes, system and service
, parameters, and the underlying platforms.
◍ Change Management Process.
Answer: Process•Verify existence/adherence to change management
procedure•Identify business process owners/administratorsChange
Requests•Verify change requests identify requestor, rationale, change
requirements•Determine how change requests are captured, managed,
prioritized/evaluatedChange Making•Changes made in separate design
environment, documentation updated, training•History of changes captured
for trend analysis•Signoffs on changes made as needed by requestorChange
Testing•Existence of relevant but separate test environment•Performance of
unit, regression, integration testingChange Implementation•Verify approval
of changes into production/back-out procedures•Developer/user signoff on
implementation
◍ bug bounty program.
Answer: is a deal offered by many websites, organizations and software
developers by which individuals can receive recognition and compensation
for reporting bugs, especially those pertaining to exploits and vulnerabilities
◍ Software updates:.
Answer: Updating OS with vendor provided fixes.•Defects are identified
either by end users or by vendors.•Vendors release fixes - patches - to
fix/mitigate the defect. (Such as Windows and Office Update)
◍ What OSX/Linux tool helps with auditing.
Answer: Both OSs have a built in patch manager
◍ Change Management Risks:.
Answer: failed change or rejection of change
◍ Infrastructure Maintenance.
Answer: Develop a strategy and plan for infrastructure maintenance, and
ensure that changes are controlled in line with the organization's change
management procedure. Include periodic reviews against business needs,
patch management, upgrade strategies, risks, vulnerabilities assessment and
80%) CERTIFICATION SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◍ Steps in Patch Management.
Answer: 1. Inventory systems and configuration2. Identify new risks,
vulnerabilities3. Identify new patches4. Weigh patching risks5. Schedule
patch acquisition6. Verify patch integrity7. Test patches before deployment
(Regression testing: to ensure that previously developed and tested software
still functions properly after a patch.)8. Deploy the patches9.
Repeat•Automate patching activities, patch management tools•Lock down
patch procedures
◍ Technological Infrastructure Acquisition Plan.
Answer: •Produce a plan for the acquisition, implementation and
maintenance of the technological infrastructure that meets established
business functional and technical requirements and is in accord with the
organization's technology direction.
◍ •HP: 44% of breaches attributed to.
Answer: patched vulnerabilities over 2 years old
◍ What windows tool helps with auditing.
Answer: MSCCM
◍ Patch Planning.
Answer: Verify that patch is compatible with your system
◍ Change Standards and Procedures.
Answer: Set up formal change management procedures to handle in a
standardized manner all requests (including maintenance and patches) for
changes to applications, procedures, processes, system and service
, parameters, and the underlying platforms.
◍ Change Management Process.
Answer: Process•Verify existence/adherence to change management
procedure•Identify business process owners/administratorsChange
Requests•Verify change requests identify requestor, rationale, change
requirements•Determine how change requests are captured, managed,
prioritized/evaluatedChange Making•Changes made in separate design
environment, documentation updated, training•History of changes captured
for trend analysis•Signoffs on changes made as needed by requestorChange
Testing•Existence of relevant but separate test environment•Performance of
unit, regression, integration testingChange Implementation•Verify approval
of changes into production/back-out procedures•Developer/user signoff on
implementation
◍ bug bounty program.
Answer: is a deal offered by many websites, organizations and software
developers by which individuals can receive recognition and compensation
for reporting bugs, especially those pertaining to exploits and vulnerabilities
◍ Software updates:.
Answer: Updating OS with vendor provided fixes.•Defects are identified
either by end users or by vendors.•Vendors release fixes - patches - to
fix/mitigate the defect. (Such as Windows and Office Update)
◍ What OSX/Linux tool helps with auditing.
Answer: Both OSs have a built in patch manager
◍ Change Management Risks:.
Answer: failed change or rejection of change
◍ Infrastructure Maintenance.
Answer: Develop a strategy and plan for infrastructure maintenance, and
ensure that changes are controlled in line with the organization's change
management procedure. Include periodic reviews against business needs,
patch management, upgrade strategies, risks, vulnerabilities assessment and