mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A company’s change management policy requires…
A company’s change management policy requires that all changes be categorized as standard, emergency, or normal. During a server migration, a technician discovers a critical security patch must be applied immediately to prevent a data breach. Which type of change should the technician request?
⚠ Common exam trap
CompTIA often tests the distinction between 'emergency' and 'standard' changes by presenting a time-sensitive scenario where candidates mistakenly classify a critical patch as a standard change because it is a routine security update, ignoring the 'immediate' and 'critical' context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Emergency change
The scenario describes a critical security patch that must be applied immediately to prevent a data breach, which aligns with the definition of an emergency change. Emergency changes are pre-approved or fast-tracked to address urgent threats or service outages, bypassing the normal change advisory board (CAB) review process. This ensures the patch can be deployed without delay to mitigate the risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standard change
Why it's wrong here
A standard change is a pre-authorized, low-risk, and frequently performed change, typically following a documented procedure. While efficient for routine tasks like adding a user account or installing a standard application, it is entirely unsuitable for an urgent security patch. Security patches address critical vulnerabilities that are often unforeseen and carry high potential impact, demanding a more immediate and specific response than a pre-approved, generic process allows.
- ✓
Emergency change
Why this is correct
An emergency change is specifically designed for situations that demand immediate action to resolve a critical incident or prevent a major service disruption, such as an active security breach or a widespread system failure. This type of change allows for an expedited approval process, often bypassing some standard review steps, to deploy critical fixes like security patches without delay. Post-implementation review and documentation are still required to ensure proper governance and learning.
- ✗
Normal change
Why it's wrong here
A normal change follows the full change management process, including detailed planning, impact assessment, formal approval from multiple stakeholders, and scheduled implementation. This comprehensive approach is ideal for planned upgrades, new service deployments, or significant configuration changes where thorough risk analysis and coordination are paramount. However, the inherent delays introduced by this structured approval and scheduling cycle make it impractical and dangerously slow for deploying an urgent security patch.
- ✗
Service request
Why it's wrong here
A service request is a formal request from a user for a standard service or information, such as a password reset, access to a shared drive, or installation of approved software. It is a user-initiated transaction for existing services, not a procedure for implementing changes to the underlying IT infrastructure or addressing critical system vulnerabilities. Therefore, it is fundamentally the wrong category for deploying an urgent, company-wide security patch.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.