mediumMultiple ChoiceObjective-mapped
220-1202 Practice Question: A security incident occurs when an unauthorized…
A security incident occurs when an unauthorized user gains access to a server because a technician left a default password unchanged after a system rebuild. The rebuild was documented, but the password change was not. What documentation failure does this highlight?
⚠ Common exam trap
CompTIA often tests the distinction between a change log's requirement to list specific changes versus broader change management processes like approval or review, leading candidates to confuse a documentation failure with a procedural one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The change log did not list the specific configuration changes made.
The documentation failure is that the change log did not list the specific configuration changes made. In this scenario, the system rebuild was documented, but the critical detail of changing the default password was omitted. Proper change management requires that every configuration change, including password updates, be explicitly recorded in the change log to ensure accountability and traceability. Without this record, the security incident occurred due to an undocumented deviation from security best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The change log did not include a rollback plan.
Why it's wrong here
While a rollback plan is a crucial component of robust change management, designed to mitigate risks by allowing a system to revert to a known good state if a change fails, its absence is not the direct cause of an unauthorized user gaining access. The primary issue in this scenario is the lack of documentation for the specific password change, which created an unknown credential, rather than the inability to undo the entire system rebuild.
- ✓
The change log did not list the specific configuration changes made.
Why this is correct
A comprehensive change log is absolutely fundamental for maintaining system security, integrity, and accountability within an IT environment. Omitting specific configuration details, such as a password update, creates a critical security vulnerability by leaving an undocumented credential or 'backdoor.' This lack of transparency directly enables unauthorized access because the change cannot be tracked, audited, or properly managed by authorized personnel.
- ✗
The change request was not approved by the change advisory board.
Why it's wrong here
Formal approval by a Change Advisory Board (CAB) is a vital governance step that ensures changes are necessary, properly planned, and assessed for potential risks before implementation. While bypassing CAB approval represents a significant process breakdown and increases risk, the direct cause of the security incident (unauthorized access) stems from the *undocumented nature* of the change itself. Even an approved change, if not thoroughly documented, could lead to the same security vulnerability.
- ✗
The technician did not perform a post-implementation review.
Why it's wrong here
A post-implementation review (PIR) is a critical step to verify the success of a change, confirm expected outcomes, and identify any unforeseen impacts or issues after deployment. While a PIR might have eventually uncovered the undocumented password change, it is a reactive measure. The root cause of the security incident is the proactive failure to properly document the change *as it occurred*, which is a fundamental aspect of secure and accountable change management practices.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.