I would run each step separately as a rule. That way its easy to see step completing and running PrepareAD needs to be run separately to ensure the perms changes are made in the forest and lets you verify that each step updated the AD forest
Setup.exe /IAcceptExchangeServerLicenseTerms /PrepareSchema
Setup.exe /IAcceptExchangeServerLicenseTerms /PrepareAD
Setup.exe /IAcceptExchangeServerLicenseTerms /PrepareDomain
Then follow that doc to upgrade: https://learn.microsoft.com/en-us/exchange/plan-and-deploy/install-cumulative-updates?view=exchserver-2019
If you do not have any mailboxes on prem, you really dont need to put into maint mode unless you are using a load balancer that checks that
Once the latest CU is applied, install the latest critical security patch