220-1102 Operational Procedures Practice Question
A company requires all changes to production systems to be approved by the Change Advisory Board (CAB). A technician receives an urgent request from a manager to apply a critical security patch that fixes a zero-day vulnerability. The patch requires a reboot, and the server is currently in use. The CAB is not scheduled to meet for another week. Which of the following is the BEST course of action?
⚠ Common exam trap
The trap here is that candidates may prioritize security over process (choosing A) or process over security (choosing B), failing to recognize that a formal emergency change procedure exists to handle such conflicts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request an emergency change approval from the CAB chair or a designated authority
It follows the change management process while addressing the urgency of a zero-day vulnerability. An emergency change approval from the CAB chair or designated authority allows the technician to bypass the standard weekly meeting, ensuring the critical security patch is applied promptly without violating company policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately because security is the top priority
Why it's wrong here
Applying the patch immediately without formal approval violates the change management process that exists precisely to prevent undocumented and uncoordinated modifications. Even when a zero-day is being exploited, the proper course is to invoke the emergency change procedure, which provides a rapid but controlled approval from the CAB chair or an authorized representative. Skipping that step can result in configuration drift, missing rollback plans, and audit non-compliance, while still not being significantly faster than a well-executed emergency change.
- ✗
Wait for the next CAB meeting to get formal approval
Why it's wrong here
Waiting for the next regularly scheduled CAB meeting introduces an unacceptable delay when a critical vulnerability is actively being exploited, as the mean time to remediate could stretch to a week or more. The change management framework expects urgent patches to go through the emergency change path, where a designated authority can grant approval within hours, and the full CAB ratifies the decision retroactively at its next meeting. Denying this urgency can lead to a security breach, which is a far greater organizational risk than the carefully managed risk of an emergency change.
- ✓
Request an emergency change approval from the CAB chair or a designated authority
Why this is correct
Requesting an emergency change approval from the CAB chair or a designated authority is the correct action because it provides the necessary speed while preserving the governance and documentation requirements of change management. The emergency change advisory board (ECAB) or a pre-authorized individual assesses the risk, verifies the rollback plan, and approves the patch, after which a standard post-implementation review is conducted. This approach ensures the change is recorded in the configuration management system, so auditors can see that the patch was intentional, risk-assessed, and authorized, not a rogue action.
- ✗
Schedule the patch for the next maintenance window without seeking formal approval
Why it's wrong here
Scheduling the patch for the next maintenance window without seeking formal approval circumvents the change control process entirely, since even a planned outage requires an approved change request with a defined implementation and rollback plan. The absence of a formal record means the change is unapproved, may violate organizational policy, and leaves no documented baseline for troubleshooting if the patch causes issues. Additionally, this option conflates the approval step with the scheduling step; the change must be authorized by the CAB or an emergency authority regardless of when it will be applied.
Go deeper
Related to this question
Learn chapter
Windows Disk Management
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.