220-1102 Operational Procedures Practice Question
A technician has a change request approved by the CAB to apply a security patch to a critical file server. The scheduled maintenance window is from 2:00 AM to 4:00 AM. The technician arrives at 2:00 AM and finds that a user is still logged in and running a long data migration job that will not complete until 3:30 AM. The user is not responding to messages. Which of the following should the technician do FIRST?
⚠ Common exam trap
A common mix-up: candidates assume an approved change request and a scheduled maintenance window give them authority to proceed regardless of active user sessions, ignoring the operational risk of data loss or corruption from interrupting a running job.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wait for the user to finish or contact the user's manager to reschedule.
The technician must prioritize data integrity and user safety over the maintenance window. Forcefully logging off a user or rebooting during a long data migration could corrupt data or cause job failure, violating change management best practices. The approved change request does not override the need to avoid disrupting active critical processes, and the technician should wait or escalate to the user's manager to reschedule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proceed with the patch installation and reboot immediately, as the maintenance window has started.
Why it's wrong here
The maintenance window's start does not override the need to avoid disrupting active user work. If a user has unsaved data or a critical job is running, immediate reboot can cause data loss or corruption. Best practice is to coordinate within the window, not to blindly act at the first second. The approved change permits execution, but it must be implemented with minimal impact.
- ✗
Forcefully log off the user and proceed, as the change is approved.
Why it's wrong here
Forcefully terminating a user's session without warning can cause unsaved work to be lost and may leave files or databases in an inconsistent state. Even with an approved change, you must not intentionally disrupt the user; instead, you should notify them and allow a graceful exit. The approval does not grant license to forcibly interrupt users.
- ✓
Wait for the user to finish or contact the user's manager to reschedule.
Why this is correct
This is the correct approach: it balances the approved change with operational continuity. Allowing the user to finish ensures no data loss and maintains user relations, while contacting the manager provides a structured way to reschedule within the maintenance window if the user will be busy for an extended time. It demonstrates change management best practices by prioritizing minimal disruption.
- ✗
Cancel the change and submit a new request for a later date.
Why it's wrong here
Cancelling the entire change is excessive because the approval is still valid and the maintenance window typically allows flexibility. A short delay to wait for the user or to coordinate with their manager is far more efficient than going through the full CAB approval process again. Unnecessary cancellation wastes time and effort and violates the principle of minimizing disruption.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.