A Windows Server 2012 administrator discovers an unpatched vulnerability with a CVSS score of 9.8. Using risk-based patching, which action should be taken first?
-
A
Schedule the patch for the next quarterly maintenance window
-
B
Apply the patch immediately after testing in a lab environment
-
C
Document the vulnerability and accept the risk
-
D
Wait for vendor confirmation before patching