220-1102 · topic practice

Operational Procedures practice questions

Use this page to practise 220-1102 Operational Procedures practice questions. The goal is not to memorise dumps, but to understand the concept, review the explanation and improve your exam readiness.

20 questionsDomain: Operational Procedures

What the exam tests

What to know about Operational Procedures

Operational Procedures questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Practice set

Operational Procedures questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Full question →

A company's change management policy requires all server changes to be approved by the Change Advisory Board (CAB). A technician discovers that a critical database server's operating system needs a security patch to comply with a new regulatory requirement that takes effect in one week. The patch has a known risk of causing service downtime. The next scheduled CAB meeting is in two weeks. What should the technician do FIRST?

Question 2mediummultiple choice
Full question →

A change advisory board (CAB) approves an emergency change to apply a critical security patch to a critical server. After the patch is applied and the server is verified operational, the technician completes the documentation. According to change management best practices, what post-implementation step is unique to emergency changes?

Question 3mediummultiple choice
Full question →

A change request to update the firmware on a network switch has been approved by the Change Advisory Board (CAB) and is scheduled for a maintenance window. During the implementation, the technician discovers that the downloaded firmware file is corrupted. The technician has verified that a backup configuration file exists. According to change management best practices, what should the technician do FIRST?

Question 4mediummultiple choice
Full question →

A company's help desk receives a report that multiple users cannot access the internet. The technician quickly discovers that the main router has failed. The technician immediately swaps the router with a spare, which restores connectivity. According to change management best practices, what should the technician do NEXT?

Question 5hardmultiple choice
Full question →

A company policy requires that all printed documents containing sensitive customer data must be collected immediately from the printer. A technician observes that an employee printed a report containing customer Personally Identifiable Information (PII) and left it in the printer tray for over an hour. Which security principle has been violated?

Question 6mediummultiple choice
Full question →

A technician discovers that a user's workstation is infected with a Trojan that is logging keystrokes and capturing login credentials. The technician has already disconnected the computer from the network. According to standard incident response procedures, what should the technician do NEXT?

Question 7easymultiple choice
Full question →

A help desk technician receives a call from a user who states they clicked on a link in an email that appeared to be from the company's CEO requesting urgent action. The user entered their username and password on the resulting webpage. Which of the following is the FIRST step the technician should take according to incident response procedures?

Question 8mediummultiple choice
Full question →

A technician has completed a standard change to replace a failed hard drive in a server. After confirming the server is operational, the technician updates the change request ticket with the completion time and status. According to change management best practices, what documentation step should the technician ensure is completed within 24 hours?

Question 9easymultiple choice
Full question →

A technician finds an unknown USB flash drive in the company parking lot. The drive is labeled 'Confidential Q4 Results'. According to operational procedures, what should the technician do?

Question 10hardmultiple choice
Full question →

A security analyst suspects that a user's workstation is infected with a rootkit that has compromised the kernel. The workstation is still operational, and the analyst needs to capture forensic evidence. Which of the following actions should the analyst take FIRST to preserve the integrity of the evidence?

Question 11mediummultiple choice
Full question →

A technician has completed the implementation of an approved change to replace all network switches in a branch office with new models. The deployment was successful, and all switches are functioning correctly. According to change management best practices, what is the NEXT step the technician should take?

Question 12hardmultiple choice
Full question →

A security technician has confirmed that a user's workstation is infected with ransomware that has encrypted local files. The technician immediately isolated the system by disconnecting the network cable and then created a forensic image of the hard drive for evidence. According to standard incident response procedures, what should the technician do NEXT?

Question 13mediummultiple choice
Full question →

A technician has completed a scheduled maintenance task to replace a failed hard drive in a server. The new drive is installed and the server is back online and functioning normally. According to best practices, what should the technician do NEXT?

Question 14easymultiple choice
Full question →

A technician is implementing a change to deploy new accounting software to 20 workstations. The change has been approved by the Change Advisory Board (CAB). During the deployment, the technician discovers that three workstations have incompatible hardware. According to change management best practices, what should the technician do FIRST?

Question 15mediummultiple choice
Full question →

A small business owner wants to ensure that employees follow a consistent and documented process when handling sensitive customer data. Which type of document should the technician recommend to outline the step-by-step procedures?

Question 16mediummultiple choice
Full question →

A technician has an approved change request to deploy a new accounting software package to 20 workstations. During the rollout on the first workstation, the technician discovers that the software requires a newer version of a runtime library that is not installed. The technician checks the remaining workstations and finds that 15 of them already have the required runtime, but five older workstations do not. According to change management best practices, what should the technician do FIRST?

Question 17mediummultiple choice
Full question →

A technician has a change request approved by the CAB to apply a security patch to a critical file server. The scheduled maintenance window is from 2:00 AM to 4:00 AM. The technician arrives at 2:00 AM and finds that a user is still logged in and running a long data migration job that will not complete until 3:30 AM. The user is not responding to messages. Which of the following should the technician do FIRST?

Question 18hardmultiple choice
Full question →

A technician is called to investigate a potential data breach involving client PII. The technician has identified the affected systems and has taken screenshots of the current state. According to proper incident response procedures, what should the technician do NEXT?

Question 19easymultiple choice
Full question →

A technician identifies that a workstation is actively infected with a worm that is spreading to other computers on the network. What is the technician's FIRST step according to incident response procedures?

Question 20hardmultiple choice
Full question →

A technician has received approval from the Change Advisory Board (CAB) to update the firmware on a critical database server. The change window is scheduled for 1:00 AM. At 12:45 AM, the technician begins the update, but mid-process the server loses power due to an electrical fault. Upon power restoration, the server fails to boot. The technician has a verified full backup. According to change management and incident response procedures, what should the technician do FIRST?

Watch out for

Common Operational Procedures exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Operational Procedures sessions

Start a Operational Procedures only practice session

Every question in these sessions is drawn from the Operational Procedures domain — nothing else.

Related practice questions

Related 220-1102 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 220-1102 exam test about Operational Procedures?
Operational Procedures questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Operational Procedures questions in a focused session?
Yes — the session launcher on this page draws every question from the Operational Procedures domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 220-1102 topics?
Use the topic links above to move to related areas, or go back to the 220-1102 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 220-1102 exam covers. They are not copied from any real exam or dump site.