Courseiva
mediumMultiple Choice

220-1202 Practice Question: A technician is configuring a new server and…

A technician is configuring a new server and follows a documented standard operating procedure (SOP). After completion, the technician realizes the SOP is outdated and omits a critical security setting. What should the technician do?

⚠ Common exam trap

Test-takers frequently think following the SOP exactly is always correct, but CompTIA A+ tests the principle that security and risk mitigation override strict adherence to outdated documentation when a known vulnerability is identified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the missing setting and update the SOP to include it.

The technician discovered a security gap in the SOP that could leave the server vulnerable. The proper action is to immediately apply the missing critical security setting to protect the server, then update the SOP to reflect the correct procedure. This aligns with change management best practices where security findings take precedence over outdated documentation, and the SOP must be corrected to prevent future misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply the missing setting and update the SOP to include it.

    Why this is correct

    Applying the missing security setting closes the vulnerability immediately, and updating the SOP prevents recurrence for future builds. This satisfies both the security requirement and the documentation control, rather than leaving the server misconfigured or the procedure stale.

  • ✗

    Ignore the missing setting since the SOP was followed.

    Why it's wrong here

    Leaving the critical security setting unapplied leaves the server exposed, regardless of SOP compliance. It is tempting because following documented procedure appears defensible, yet the technician must apply the setting and raise the SOP deficiency, since adherence to an outdated document does not excuse a known security gap on a production server.

  • ✗

    Submit a change request to update the SOP without applying the setting.

    Why it's wrong here

    Raising a change request to update the SOP without applying the setting leaves the new server missing a critical security control until the document is revised. It is tempting because change management governs documentation updates, but the setting must be applied now, with the SOP correction submitted alongside, not instead of, remediation.

  • ✗

    Revert the server configuration and wait for an updated SOP.

    Why it's wrong here

    Reverting the server and waiting for an updated SOP leaves the system unconfigured and delays deployment without closing the security gap. It is tempting as a cautious rollback, yet the technician should apply the missing setting immediately and then submit the SOP update, since reverting neither secures the server nor corrects the outdated document.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.