Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A company requires all changes to production systems to be approved by the Change Advisory Board (CAB). A technician receives an urgent request from a manager to apply a critical security patch that fixes a zero-day vulnerability. The patch requires a reboot, and the server is currently in use. The CAB is not scheduled to meet for another week. Which of the following is the BEST course of action?

⚠ Common exam trap

The trap here is that candidates may prioritize security over process (choosing A) or process over security (choosing B), failing to recognize that a formal emergency change procedure exists to handle such conflicts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request an emergency change approval from the CAB chair or a designated authority

It follows the change management process while addressing the urgency of a zero-day vulnerability. An emergency change approval from the CAB chair or designated authority allows the technician to bypass the standard weekly meeting, ensuring the critical security patch is applied promptly without violating company policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the patch immediately because security is the top priority

    Why it's wrong here

    Applying the patch immediately without formal approval violates the change management process that exists precisely to prevent undocumented and uncoordinated modifications. Even when a zero-day is being exploited, the proper course is to invoke the emergency change procedure, which provides a rapid but controlled approval from the CAB chair or an authorized representative. Skipping that step can result in configuration drift, missing rollback plans, and audit non-compliance, while still not being significantly faster than a well-executed emergency change.

  • ✗

    Wait for the next CAB meeting to get formal approval

    Why it's wrong here

    Waiting for the next regularly scheduled CAB meeting introduces an unacceptable delay when a critical vulnerability is actively being exploited, as the mean time to remediate could stretch to a week or more. The change management framework expects urgent patches to go through the emergency change path, where a designated authority can grant approval within hours, and the full CAB ratifies the decision retroactively at its next meeting. Denying this urgency can lead to a security breach, which is a far greater organizational risk than the carefully managed risk of an emergency change.

  • ✓

    Request an emergency change approval from the CAB chair or a designated authority

    Why this is correct

    Requesting an emergency change approval from the CAB chair or a designated authority is the correct action because it provides the necessary speed while preserving the governance and documentation requirements of change management. The emergency change advisory board (ECAB) or a pre-authorized individual assesses the risk, verifies the rollback plan, and approves the patch, after which a standard post-implementation review is conducted. This approach ensures the change is recorded in the configuration management system, so auditors can see that the patch was intentional, risk-assessed, and authorized, not a rogue action.

  • ✗

    Schedule the patch for the next maintenance window without seeking formal approval

    Why it's wrong here

    Scheduling the patch for the next maintenance window without seeking formal approval circumvents the change control process entirely, since even a planned outage requires an approved change request with a defined implementation and rollback plan. The absence of a formal record means the change is unapproved, may violate organizational policy, and leaves no documented baseline for troubleshooting if the patch causes issues. Additionally, this option conflates the approval step with the scheduling step; the change must be authorized by the CAB or an emergency authority regardless of when it will be applied.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.