mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A company’s change management policy requires all…
A company’s change management policy requires all changes to be approved by the Change Advisory Board (CAB) before implementation. A technician applies an emergency security patch to a critical server without CAB approval because the vulnerability is being actively exploited. What should the technician do after applying the patch?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the change and submit an emergency change request for retroactive approval.
Even in emergency changes, documentation and retroactive approval are required. The technician must document the change and notify the CAB as soon as possible to obtain retroactive approval, ensuring compliance with change management policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wait for the next CAB meeting to report the change.
Why it's wrong here
Waiting for a scheduled Change Advisory Board (CAB) meeting to report an emergency change is inappropriate because it introduces significant delay in formally recognizing and approving a critical system modification. This inaction could leave the change unrecorded in the official change management system for an extended period, potentially violating compliance requirements and hindering future troubleshooting or auditing efforts, as immediate documentation and notification are paramount for emergency actions.
- ✓
Document the change and submit an emergency change request for retroactive approval.
Why this is correct
For emergency changes, the immediate priority is to implement the necessary fix to restore service or mitigate a critical threat. Following this, the correct procedure mandates thoroughly documenting the change, including its rationale, steps taken, and impact, and then promptly submitting an emergency change request to the Change Advisory Board (CAB) for retroactive review and formal approval. This ensures accountability, maintains the integrity of the change management process, and provides a crucial audit trail.
- ✗
Revert the patch and wait for CAB approval.
Why it's wrong here
Reverting a critical security patch, especially one applied to address an active exploit or urgent vulnerability, would deliberately reintroduce known security weaknesses into the system. This action would leave the system exposed to significant and immediate risks, potentially leading to further compromise, data loss, or service disruption, completely undermining the initial emergency action taken to protect the environment.
- ✗
Delete the change log entry to avoid accountability.
Why it's wrong here
Deleting change log entries is a serious breach of IT governance, ethical conduct, and organizational policy. This action destroys the audit trail, obscures accountability for system modifications, and prevents proper analysis during incident response or future troubleshooting, which can lead to severe disciplinary action, regulatory non-compliance, and a complete erosion of trust in the integrity of the change management system.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.