220-1102 Operational Procedures Practice Question
A change advisory board (CAB) approved an emergency change to apply a critical security patch to a web server. After applying the patch, the technician documents the change. What documentation step is uniquely required for an emergency change?
⚠ Common exam trap
Many exam-takers confuse standard change documentation steps (like updating asset inventory or creating knowledge base articles) with the unique emergency change requirement, failing to recognize that post-implementation CAB approval is the critical step that distinguishes an emergency change from a normal change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain post-implementation approval from the CAB.
Emergency changes bypass the normal change advisory board (CAB) approval process before implementation to address critical security threats quickly. The unique documentation requirement for an emergency change is to obtain post-implementation approval from the CAB, ensuring that the change is retrospectively reviewed and formally accepted. This step is mandated by ITIL best practices to maintain governance and audit trails for changes that were implemented without prior authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Obtain post-implementation approval from the CAB.
Why this is correct
Emergency changes bypass the standard advance CAB approval because speed is critical (e.g., patching a zero-day vulnerability). To maintain governance and accountability, the CAB must still perform a post-implementation review, ratifying that the change was justified, properly evaluated, and documented correctly. This retrospective approval is a mandatory closure step in the emergency change process, and it is the single action that distinguishes an emergency change from an unauthorized one.
- ✗
Update the asset inventory with the patch version.
Why it's wrong here
Updating the asset inventory with the new patch version is a routine configuration management task that applies to every change—whether standard, normal, or emergency. The CMDB must reflect the current state of all assets for accurate auditing and planning, but this update does not validate the emergency change's necessity or provide the required governance oversight. Thus, it is a good practice but not the unique post-implementation step mandated for emergency changes.
- ✗
Create a knowledge base article about the patch.
Why it's wrong here
Although a knowledge base article about the patch—including its symptoms, remediation, and known issues—is useful for self-service and support efficiency, it is not a formal requirement of emergency change management. Creating documentation does not constitute a review or approval by the CAB, nor does it satisfy the need to audit whether the emergency change was warranted. The article would only be a supplementary artifact, not the conclusive step that closes the emergency change record.
- ✗
Schedule the next change window for future patches.
Why it's wrong here
Scheduling a future change window for additional patches is part of proactive maintenance and release planning; it does not address the governance gap left by an emergency change that skipped pre-approval. An emergency change's key obligation is to return for retrospective CAB review to confirm that the immediate action was necessary and acceptable in the absence of prior authorization. Planning future maintenance does not evaluate the past emergency change's validity or capture lessons learned.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
POST
Power-On Self-Test (POST) is a diagnostic process that a computer runs when it first powers on to check that essential hardware components are working correctly before loading the operating system.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A change advisory board (CAB) approves an emergency change to apply a critical security patch to a critical server. After the patch is applied and the server is verified operational, the technician completes the documentation. According to change management best practices, what post-implementation step is unique to emergency changes?
medium- ✓ A.Schedule a post-implementation review within 30 days
- B.Notify all users about the change
- C.Revert the change if not approved later
- D.Obtain verbal approval from the CEO
Why A: Per change management best practices (ITIL), emergency changes bypass the normal CAB approval process and require a post-implementation review (PIR) within 30 days to validate the change, assess any unplanned impacts, and ensure proper documentation. This step is unique to emergency changes as it compensates for the lack of pre-approval by formally confirming the change's success and capturing lessons learned.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.