Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A change management policy requires that all changes to production systems be approved by the Change Advisory Board (CAB) before implementation. A technician has discovered a critical security vulnerability on a file server that requires immediate patching to prevent a potential data breach. The technician has already obtained verbal approval from the IT manager. What should the technician do NEXT according to change management best practices?

⚠ Common exam trap

Watch out — candidates often confuse 'verbal approval from a manager' with formal authorization, or think that urgency alone justifies immediate action without following the documented emergency change process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the change with the justification for urgency and submit it to the CAB for emergency approval

Change management best practices require that even urgent changes follow a documented emergency change process. The technician has identified a critical security vulnerability, which qualifies as an emergency change, but verbal approval alone is insufficient; the change must be formally documented with justification and submitted to the Change Advisory Board (CAB) for emergency approval. This ensures proper oversight, risk assessment, and audit trail while still allowing rapid response to security threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement the patch immediately since time is critical, then document it later

    Why it's wrong here

    While time is a genuine concern, implementing a patch outside the change process creates an undocumented, unauthorized baseline change and eliminates the opportunity to assess rollback plans, dependencies, and potential conflicts with existing configurations. The policy likely mandates that even emergency changes obtain at least expedited approval and a post-change review; 'document later' often becomes 'never documented.' This makes the organization non-compliant and exposes it to audit findings and an unverified, potentially unstable production environment.

  • ✓

    Document the change with the justification for urgency and submit it to the CAB for emergency approval

    Why this is correct

    This response correctly uses the emergency change pathway: the technician records the change request, provides a clear business justification for urgency, identifies affected systems, and presents it to the CAB or its designated emergency responder for immediate, risk-based review. Emergency CAB approval is typically granted via a special quorum or virtual meeting, allowing the required authorization to be obtained within hours instead of waiting for a regular meeting. The documented record enables post-implementation verification, rollback execution, and a clear audit trail, satisfying the policy's intent while addressing the critical vulnerability.

  • ✗

    Rely solely on the verbal approval from the IT manager and apply the patch

    Why it's wrong here

    Verbal approval from an IT manager, even if that manager has seniority, bypasses the CAB's structured risk-impact analysis and fails to create the authoritative change record required for auditing and configuration management. The IT manager may not have delegated authority to approve changes unless explicitly specified in the policy, and verbal approval cannot capture rollback steps, test results, or affected configuration item details. This leaves the organization unable to prove that a formal decision was made, which violates compliance and makes incident recovery harder.

  • ✗

    Refuse to apply the patch until the next scheduled CAB meeting

    Why it's wrong here

    Refusing to take any action until the next scheduled CAB meeting ignores the fact that change management policies typically include an emergency change procedure for time-sensitive vulnerabilities. A critical patch is often a security fix that should be deployed within the vendor-defined window; waiting days or weeks can leave the environment exposed to an exploited CVE. The correct course is to use that expedited process, not to postpone the change entirely, because the same risk-approval controls still apply in compressed form.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.