220-1102 Operational Procedures Practice Question
A company's change management policy requires all server changes to be approved by the Change Advisory Board (CAB). A technician discovers that a critical database server's operating system needs a security patch to comply with a new regulatory requirement that takes effect in one week. The patch has a known risk of causing service downtime. The next scheduled CAB meeting is in two weeks. What should the technician do FIRST?
⚠ Common exam trap
Many candidates assume any urgent need justifies immediate action without approval, but CompTIA emphasizes that even emergency changes must follow a documented process—never bypassing change management entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit an urgent change request and obtain emergency approval
The correct first step is to submit an urgent change request and obtain emergency approval because the change management policy requires CAB approval for all server changes, but the regulatory deadline (one week) is sooner than the next scheduled CAB meeting (two weeks). Emergency change processes are designed for exactly this scenario—where a critical security patch is needed to meet compliance but carries a known risk of downtime. By following the emergency approval path, the technician ensures the change is documented, risk-assessed, and authorized outside the normal CAB cycle, maintaining both compliance and policy adherence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Submit an urgent change request and obtain emergency approval
Why this is correct
Emergency change requests are a recognized exception within change management policy, specifically designed for urgent situations where a critical compliance or security risk exists. This option allows the patch to be applied immediately while still documenting the change, assessing risk, and scheduling a post-implementation review, thereby satisfying both the regulatory deadline and the policy's accountability requirements.
- ✗
Wait for the next CAB meeting to submit the request
Why it's wrong here
Waiting for the next scheduled CAB meeting introduces a delay that directly conflicts with the compliance deadline referenced in the scenario. Standard CAB meetings occur at fixed intervals, and deferring the change until then means the system remains out of compliance during the interim, exposing the company to legal penalties, regulatory sanctions, or audit failures that the patch was meant to prevent.
- ✗
Implement the patch immediately without formal approval
Why it's wrong here
Applying the patch without any formal approval violates the mandatory change management policy, which exists to ensure all changes are evaluated for risk, tested, and equipped with a rollback plan regardless of urgency. An unapproved change creates an undocumented divergence from the baseline, leading to configuration drift, potential operational outages, and audit findings, while still not following the legitimate emergency process.
- ✗
Implement a technical workaround to satisfy the regulation without patching
Why it's wrong here
A technical workaround may temporarily mask the symptom but does not eliminate the underlying vulnerability that the patch addresses, leaving the system exposed to the exact security or compliance issue the regulation targets. Additionally, workarounds often introduce their own stability risks, may not fully satisfy the regulatory requirement, and still require the actual patch later, compounding the compliance deadline problem rather than resolving it.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Regulatory requirement
A regulatory requirement is a rule issued by a government or industry authority that organizations must follow, often to protect data, ensure safety, or maintain fair practices.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.