220-1102 Operational Procedures Practice Question
A company's change management policy requires all infrastructure changes to be approved by the Change Advisory Board (CAB). A technician discovers a critical security vulnerability that requires immediate patching before the next scheduled CAB meeting. What is the best course of action?
⚠ Common exam trap
Watch out — candidates often think bypassing the CAB entirely (Option A) is acceptable for security emergencies, but the exam emphasizes that even urgent changes must follow the documented emergency change process to maintain policy compliance and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request an emergency change approval from the CAB chairperson or designated authority
Change management policies typically include an emergency change process that allows the CAB chairperson or designated authority to approve critical patches outside of regular meetings. This balances the need for rapid remediation of a security vulnerability with the requirement for oversight and documentation, ensuring compliance without exposing the company to unnecessary risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bypass the CAB and implement the patch immediately to prevent a breach
Why it's wrong here
Bypassing the CAB and deploying a security patch without prior approval is a process violation that creates uncoordinated change risk. Although the intent is to prevent a breach, the lack of review means the patch could conflict with other scheduled changes, introduce system instability, and leave the organization without a rollback plan. Additionally, skipping the mandated approval path exposes the company to audit findings and policy noncompliance, which can have regulatory consequences.
- ✓
Request an emergency change approval from the CAB chairperson or designated authority
Why this is correct
An emergency change authorization from the CAB chairperson or another designated authority is the correct way to handle urgent security patches. This process permits a single decision-maker to grant approval outside the normal CAB meeting schedule, while still requiring documentation, impact assessment, and a rollback plan. It preserves the intent of change management—oversight and risk control—even when timing is critical.
- ✗
Wait for the next scheduled CAB meeting to present the change request
Why it's wrong here
Waiting for the next scheduled CAB meeting introduces an unacceptable delay for a critical vulnerability, leaving an active attack surface within the organization. During the wait, the system remains exploitable, allowing attackers to potentially gain a foothold against an unpatched flaw. A change this urgent should never be deferred when an emergency path exists to review and authorize it within hours rather than days.
- ✗
Implement the patch and submit a post-implementation review after the fact
Why it's wrong here
Implementing the patch first and obtaining a post-implementation review is flawed because the change was already applied before any formal authorization or risk assessment occurred. The emergency process requires that approval be secured before implementation—even if expedited—so that the change is logged with a proper RFC and rollback plan in place. A post-hoc review cannot undo an unauthorized change, and the company may be forced to accept an undocumented, unapproved alteration to its infrastructure.
Go deeper
Related to this question
Learn chapter
Browser Security Settings and Add-ons
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's change management policy requires all server changes to be approved by the Change Advisory Board (CAB). A technician discovers that a critical database server's operating system needs a security patch to comply with a new regulatory requirement that takes effect in one week. The patch has a known risk of causing service downtime. The next scheduled CAB meeting is in two weeks. What should the technician do FIRST?
hard- ✓ A.Submit an urgent change request and obtain emergency approval
- B.Wait for the next CAB meeting to submit the request
- C.Implement the patch immediately without formal approval
- D.Implement a technical workaround to satisfy the regulation without patching
Why A: The correct first step is to submit an urgent change request and obtain emergency approval because the change management policy requires CAB approval for all server changes, but the regulatory deadline (one week) is sooner than the next scheduled CAB meeting (two weeks). Emergency change processes are designed for exactly this scenario—where a critical security patch is needed to meet compliance but carries a known risk of downtime. By following the emergency approval path, the technician ensures the change is documented, risk-assessed, and authorized outside the normal CAB cycle, maintaining both compliance and policy adherence.
Variation 2. A company has a policy that all changes to network infrastructure must be approved by a supervisor before implementation. A technician notices a critical security vulnerability in a firewall that needs immediate patching. What should the technician do?
easy- A.Implement the patch immediately since it is a security emergency
- ✓ B.Follow the change management process and submit a request for approval
- C.Notify the supervisor and await verbal approval before patching
- D.Send an email notification after patching
Why B: The company policy mandates that all changes to network infrastructure must be approved through the change management process. Even in a security emergency, bypassing the process can lead to unintended consequences, such as disrupting critical services or creating new vulnerabilities. Following the process ensures proper documentation, risk assessment, and coordination, which is essential for maintaining network stability and security.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.