Lesson 2: Implementing Patch Management Flashcards

1
Q

Windows Update program

A

scans your system to determine the updates and fixes your system needs. You then have the oppor- tunity to select, download, and install each update.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Patch Tuesday

A

second Tuesday of each month when MSFT releases patches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

out-of-band patches

A

MSFT patches not released on patch Tuesday – released at other times because they are critical or time-sensitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

3 classifications for updates

A

Important updates
Recommended updates
Optional updates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Important Updates

A

significant benefits, such as improved security, privacy, and reliability. They should be installed as they become available and can be installed automatically with Windows Update.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Recommended Updates

A

address noncritical problems or help enhance your computing experience.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Optional Updates

A

include updates, drivers, or new software from Microsoft to enhance your computing experience. You need to install these manually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Three types of updates

A

Security Update
Critical Update
Service Packs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security Update

A

broadly released fix for a product-specific, security-related vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How are security updates rated?

A

Based on severity – critical, important, moderate or low

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Critical Updates

A

broadly released fix for a specific problem addressing a critical, non-security related bug.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Service Packs

A

a tested, cumulative set of hotfixes, security updates, critical updates, and updates, as well as additional fixes for problems found internally since the release of the product.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Hotfix

A

a single, cumulative package that includes one or more files that are used to address a problem in a software product, such as a software bug.

Not usually available via Win Update

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What separates hotfixes from other updates

A

made to address a specific customer situation, and they often have not gone through the same extensive testing as patches retrieved through Windows Updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

cumulative patch

A

multiple hotfixes combined into a single package

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Types of updates not available via Windows Update

A

hotfix

cumulative patch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

BITS

A

Background Intelligent Transfer Service

Performs the download when the computer’s network band- width is idle

18
Q

Automatic Updates Group Policy Setting: Automatic Update Detection Frequency

A

Specifies how frequently the Windows Update client checks for new updates. The default is a random time between 17 and 22 hours.

19
Q

Automatic Updates Group Policy Setting: Allow Automatic Updates Immediate Installation

A

Specifies whether Windows Updates will immediately install updates that don’t require the computer to be restarted.

20
Q

Automatic Updates Group Policy Setting: Turn On Recommended Updates Via Automatic Updates:

A

Determines whether client computers install both critical and recommended updates.

21
Q

Automatic Updates Group Policy Setting: No Auto-Restart for Scheduled Automatic Installations

A

Specifies that if a computer needs a restart, it will wait for a user to perform the restart.

22
Q

Automatic Updates Group Policy Setting: Re-Prompt for Restart Scheduled Installations

A

Specifies how often the Windows Update client prompts the user to restart the computer.

23
Q

Automatic Updates Group Policy Setting: Delay Restart for Scheduled Installations

A

Specifies how long the Windows Update client waits before automatically restarting.

24
Q

Automatic Updates Group Policy Setting: Reschedule Automatic Updates Scheduled Installations

A

Specifies how long Windows Update waits after a reboot before continuing with a scheduled installation that was missed previously.

25
Q

Automatic Updates Group Policy Setting: Enable Client-Side Targeting

A

Specifies which group the computer is a member of.

26
Q

Automatic Updates Group Policy Setting: Enables Windows Update Power Management to Automatically Wake up the System to Install Scheduled Updates

A

If a computer supports Wake On LAN, it automatically starts up and installs an update at the scheduled time.

27
Q

Automatic Updates Group Policy Setting: Allow Signed Updates from an Intranet Microsoft Update Services Location:

A

Specifies if Windows will install an update that is signed even if the certificate is not from Microsoft.

28
Q

WSUS

A

Windows Server Update Services
allows administrators to manage the testing & distribution of updates and other patches to computers within an organization

29
Q

Simplest WSUS configuration

A

single WSUS that downloads updates directly from Microsoft. Then the client computers get updates from the WSUS server.

30
Q

Two WSUS modes

A

Autonomous mode

Replica mode

31
Q

WSUS Mode – Autonomous mode

A

Distributed management. Updates are approved on each WSUS server, even if one WSUS server is downstream from another.

32
Q

WSUS Mode – Replica Mode

A

Central management. All downstream WSUS servers take instructions from a single upstream WSUS server. Updates approved on that server are approved on all servers.

33
Q

Computer Groups

A

Placing PCs into these allow you to specify which PCs get updates, when.

34
Q

Two ways to assign a computer to a group

A

Client-side targeting

server-side targeting

35
Q

server-side targeting

A

you manually assign the computer to a group.

36
Q

client-side targeting

A

computers are automatically assigned to a computer group by using group policies or whereby someone manually modifies the registry.

37
Q

3 WSUS logs

A

application event log
C:\Program Files\Update Services\LogFiles\Change.txt:
C:\Program Files\Update Services\LogFiles\softwareDistribution.txt:

38
Q

What does WSUS place in the WSUS logs

A

errors related to synchronization, Update Services console errors, and WSUS database errors.

39
Q

What does WSUS place in the Change.txt logs?

A

This log stores the record of every update installation, synchronization, and WSUS configuration change.

40
Q

What does WSUS place in the softwareDistribution.txt log?

A

This is a detailed log file usually used by Microsoft Support to debug a problem.

41
Q

Restarting the WSUS server on the CLI

A

Net stop wuauserv

Net start wuauserv

42
Q

SCCM

A

System Center Configuration Manager
a more versatile system that can provide remote control, patch management, software distribution, operating system deployment, network access protection, hardware inventory, and software inventory. Of course, while WSUS is free, there is a cost in deploying SCCM.