220-1102 Operational Procedures Practice Question
A company follows a strict change management process. A technician is applying a critical security patch to a web server during a scheduled maintenance window. The patch was fully tested in a lab environment and approved by the Change Advisory Board (CAB). During the installation, the technician discovers that the patch requires a software dependency that is not installed on the server. According to change management best practices, what should the technician do FIRST?
⚠ Common exam trap
A common mix-up: candidates assume a 'quick fix' like installing a missing dependency is acceptable, but CompTIA tests the strict adherence to the approved change plan and the requirement to abort and back out when any unexpected condition arises.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Abort the change and follow the backout plan to restore the server
Change management best practices require that any deviation from the approved change plan—such as an unplanned dependency—must be treated as a failed change. The technician should immediately abort the installation and execute the backout plan to restore the server to its pre-change state, then report the issue to the CAB for re-evaluation. Installing an untested dependency without prior approval violates the integrity of the change process and could introduce unforeseen instability or security risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the required dependency and then proceed with the patch
Why it's wrong here
Installing the undisclosed dependency and then proceeding with the patch exceeds the approved change scope and skips the required testing cycle. An unverified component could introduce compatibility conflicts with existing applications or security baselines, making the patched server unpredictable. Additionally, the change record would no longer reflect the actual action taken, which is a serious audit finding in a strict change management environment.
- ✓
Abort the change and follow the backout plan to restore the server
Why this is correct
Aborting the change immediately and executing the documented backout plan is the mandated first response because it restores the server to its pre-change baseline and mitigates any partial failure. The backout plan was pre-approved and tested, so it guarantees a return to a known-good state without further risk. Once stable, the change record can be updated and a new request submitted containing all dependencies.
- ✗
Contact the CAB for immediate approval of the dependency
Why it's wrong here
Contacting the CAB for immediate approval is insufficient because the server is currently in an unapproved, partially changed state, and leaving it that way while waiting for approval compounds the risk of configuration drift or an outage. Even if the CAB grants expedited approval, the dependency has not been tested against the target system, so the underlying technical uncertainty remains unresolved. The strict process requires restoring the server before any further evaluation occurs.
- ✗
Apply the patch anyway and monitor the server for issues
Why it's wrong here
Applying the patch anyway without the required dependency will likely cause the patch installation to fail or throw runtime errors, because the missing component is a prerequisite for the patch's core functions. The server could be left in a broken or inconsistent state, and the divergence from the approved change plan creates an uncontrolled configuration change. Monitoring afterward is futile because the damage or instability has already been introduced.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.