220-1102 Operational Procedures Practice Question
A critical security vulnerability has been discovered in the company's web server software. The vendor has released a patch, and the IT security team has verified it in a test environment. The change requires a server reboot, causing a 30-minute outage. The company's change management policy requires all changes to be pre-approved by the Change Advisory Board (CAB), which meets weekly on Fridays. The vulnerability is actively being exploited in the wild. What should the technician do NEXT?
⚠ Common exam trap
Candidates often assume 'active exploit' automatically justifies ignoring all change management policies, but the correct approach is to use the emergency change process to get rapid approval while still adhering to governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit an emergency change request to the CAB for immediate approval.
When a critical vulnerability is actively exploited, standard change management procedures must be bypassed via an emergency change request. The CAB can approve such requests outside of regular meetings, allowing the patch to be deployed immediately to mitigate the active threat. This balances security urgency with organizational policy compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the patch immediately without approval due to the active exploit.
Why it's wrong here
Deploying the patch immediately without approval disregards the change management process entirely, even in an emergency. A structured emergency change request ensures the patch is documented, risk-assessed, and includes a rollback plan, while bypassing approval leaves the organization with no audit trail and could introduce unforeseen side effects. The active exploit justifies expediting approval, not eliminating it.
- ✗
Wait for the next weekly CAB meeting to submit the change request.
Why it's wrong here
Waiting for the next weekly CAB meeting could leave the server vulnerable to the active exploit for days, allowing attackers to compromise sensitive data. Emergency change procedures exist precisely to handle time-sensitive security patches, and typically allow for an ad-hoc CAB conference call or a dedicated emergency approval path. Normal change scheduling is inappropriate when the risk of delay outweighs the usual review cycle.
- ✓
Submit an emergency change request to the CAB for immediate approval.
Why this is correct
Submitting an emergency change request to the CAB triggers the defined urgent-change pathway, which provides expedited but documented approval. This process compresses the review timeline—often via a subset of CAB members or an on-call approver—while still capturing the justification, risk impact, and rollback steps. It balances the need for speed with governance, and after deployment the change is fully documented and retrospectively reviewed if necessary.
- ✗
Email the IT manager for approval and apply the patch if the manager agrees.
Why it's wrong here
Emailing the IT manager for approval is insufficient because formal change management requires the CAB or its delegated authority to approve critical changes, not a single department manager. An email approval does not produce a change record, risk assessment, or rollback plan, so the organization loses the governance and audit trail needed for accountability. Even if the manager agrees, the change would be non-compliant with the change policy and could be rolled back in an audit.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.