Which approach best manages the risk of unpatched IIS vulnerabilities in a production environment?
-
A
Disabling Windows Update to avoid compatibility issues
-
B
Implementing a patch management policy with regular Windows Update cycles
-
C
Running IIS on an isolated network with no internet access only
-
D
Enabling all IIS modules to ensure compatibility with future patches