- Home
- All questions
- Question 111
CompTIA Security+ study material · question 111 of 611
An upgrade would fix a vulnerability, but the new version's cryptographic modules are not yet FIPS-validated and the organisation must use validated modules. What does this illustrate?
Show the answer
Answer: C. That patching decisions are not purely technical
An upgrade can break a compliance requirement, so the response has to weigh both obligations.
Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.1 Risk Responses