easyMultiple ChoiceObjective-mapped
220-1202 Practice Question: During a routine security audit, a technician…
During a routine security audit, a technician discovers that a server was patched out of the approved maintenance window. The patch was applied by a junior admin who was not authorized. What is the most important step to include in the incident documentation?
⚠ Common exam trap
CompTIA often tests the distinction between documenting what happened versus why it happened, and the trap here is that candidates focus on technical details (time, version, person) instead of the root cause reason that drives corrective action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The reason the patch was applied outside the maintenance window.
The most important step in incident documentation is to capture the reason the patch was applied outside the approved maintenance window. This directly addresses the root cause of the unauthorized change, which is critical for post-incident review, process improvement, and preventing recurrence. Without the reason, the documentation fails to support a meaningful root cause analysis (RCA) and corrective action planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The name of the junior admin who applied the patch.
Why it's wrong here
While the identity of the administrator is important for accountability and tracking, it does not explain the *rationale* behind the deviation from established protocol. The security audit's primary concern is understanding *why* the maintenance window was bypassed, not merely *who* performed the action, to prevent recurrence and ensure policy adherence. Knowing the name alone does not provide the context necessary for a comprehensive review of the procedural violation.
- ✓
The reason the patch was applied outside the maintenance window.
Why this is correct
The justification for applying a patch outside the designated maintenance window is paramount for proper change management and risk assessment. This documentation allows the Change Advisory Board (CAB) or security team to evaluate the urgency and necessity of the emergency change, ensuring that procedural deviations are understood, approved retroactively if warranted, and that appropriate controls are in place to minimize future occurrences. It directly addresses the procedural breach identified by the audit.
- ✗
The exact time the patch was applied.
Why it's wrong here
While precise timestamps are crucial for audit trails and correlating events, knowing the exact moment the patch was applied does not explain the *decision-making process* that led to bypassing the maintenance window. The time merely records *when* the violation occurred, not *why* the established change control procedure was circumvented, which is the core issue for a security audit. This information is secondary to the underlying cause of the policy breach.
- ✗
The patch's version number and source.
Why it's wrong here
Details such as the patch's version number and its source are important for inventory management, vulnerability tracking, and verifying the integrity of the update. However, these technical specifications do not provide insight into the procedural breach itself. The audit is focused on the *deviation from policy* regarding the maintenance window, not the technical specifics of the patch applied, making this information less critical for addressing the procedural violation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.