Lifecycle and disposal¶
An RTA is a point-in-time appliance: built for one engagement, used for that engagement, then destroyed. This page covers what that means before, during, and after testing.
Before testing: built fresh for your engagement¶
Each appliance image is produced for your engagement from a current, patched base build, loaded with the tooling the engagement needs, and issued unique credentials with an expiration. No two customers ever share an image or credentials.
During testing: nothing for you to maintain¶
The appliance is short-lived, so it does not join your patch cycle and needs no care from your team beyond staying powered on and connected.
Critical vulnerabilities are patched immediately
If a critical or severe vulnerability is disclosed in software the appliance runs (for example, a kernel or SSH vulnerability) while it is deployed, Sophos emergency-patches deployed appliances as soon as a fix has been tested. This is the one exception to the no-maintenance model.
After testing: dispose of the appliance¶
Once the engagement, and any remediation retesting, has concluded:
- Delete the VM and its disks, along with any copies of the image files your team downloaded or staged.
- On a cloud platform, also terminate the instance and delete any images or snapshots created from it during deployment.
The appliance's credentials are tied to the engagement and are expired or revoked once it ends, so a forgotten copy cannot reconnect. Deleting it is still the right hygiene.
Long-running deployments¶
Some larger testing programs keep an appliance in place beyond a single engagement. That is the rare exception: those appliances are handed over to be managed by the customer's own team, under the customer's own patching and configuration standards. If this applies to you, your engagement lead will arrange it explicitly.