Patch two servers, find the pending reboot, and report compliance

short · 45 min · Objective 3.5

Task

Patch lin-srv and lin-b the way a small patch cycle runs: list what is pending, apply security updates to one server first as the pilot, check it, then the other. Detect which server needs a reboot for the updates to take effect, and produce a compliance report that says, for each server, what it is missing.

Steps

  1. On each server, save the list of pending updates (apt list --upgradable or dnf check-update) to lab/patch/<host>-pending.txt.
  2. Patch lin-b first as the pilot: apply the updates, check its services still run, and record the result in lab/patch/pilot.txt.
  3. Patch lin-srv. On both, check whether a reboot is required (/var/run/reboot-required on Ubuntu, needs-restarting -r on Rocky) and save the result to lab/patch/<host>-reboot.txt.
  4. Write lab/patch/compliance.csv with header host,pending_before,pending_after,reboot_required,compliant, with yes or no in the last two columns, from the files, then reboot the servers that need it and update the CSV.
  5. Record in lab/patch/emergency.txt how the process would change for an actively exploited critical vulnerability on an internet-facing server.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

ls lab/patch/*-pending.txt | wc -l
grep -c . lab/patch/pilot.txt
awk -F, 'NR>1 {print $1": before "$2", after "$3", reboot "$4", compliant "$5}' lab/patch/compliance.csv
awk -F, 'NR>1 && $5=="yes" && $4=="yes" {bad++} END {print bad+0" host(s) marked compliant with a pending reboot"}' lab/patch/compliance.csv
grep -Eic 'emergency|mitigat|hours|window' lab/patch/emergency.txt

Both servers have a pending list and a compliance row, and after the reboots both are compliant with nothing pending. No host may be marked compliant while a reboot is pending: an installed but inactive update leaves the vulnerability open, which is the gap the lesson warns about.

Notes

On Windows, Get-HotFix lists installed updates, and the registry key RebootPending under Component Based Servicing marks a pending reboot. WSUS and Configuration Manager report both across a fleet.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.