Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A customer reports that after a recent software…

A customer reports that after a recent software update, their accounting application crashes every time they try to generate a report. The technician checks the change log and finds no record of any update being approved for that application. What should the technician do first?

⚠ Common exam trap

CompTIA often tests the distinction between technical troubleshooting and process compliance, trapping candidates who jump to a technical fix (restore, uninstall, or patch) instead of following the documented change management procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the unauthorized change and escalate it to the change advisory board.

The technician found an unauthorized change (the update) with no approval record. The first step in change management is to document and escalate the unauthorized change to the Change Advisory Board (CAB) to assess impact, determine root cause, and authorize remediation. Restoring or reinstalling without CAB approval could violate change control policies and introduce additional risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restore the application from the last known good backup.

    Why it's wrong here

    Restoring the application from a last known good backup is a reactive measure that bypasses critical change management protocols. This action fails to document the unauthorized software update, which is essential for identifying the root cause and preventing future occurrences. Implementing a restore without proper documentation and escalation would obscure the fact that an unapproved change took place, hindering accountability and thorough incident analysis within the IT environment.

  • Document the unauthorized change and escalate it to the change advisory board.

    Why this is correct

    Documenting the unauthorized change and escalating it to the Change Advisory Board (CAB) is the correct initial step according to CompTIA A+ and ITIL best practices. This ensures that the unapproved modification is formally recorded, allowing for proper review, impact assessment, and a structured decision-making process before any corrective actions are implemented. This approach maintains accountability, reinforces change control policies, and helps prevent similar incidents in the future by addressing the process failure.

  • Uninstall the update and reinstall the previous version of the application.

    Why it's wrong here

    Uninstalling the update and reinstalling a previous version, while seemingly a quick fix, circumvents established change management procedures. This action would constitute another unapproved change, creating further inconsistencies in the system's configuration and undermining the integrity of the change control process. It fails to address the underlying issue of why an unauthorized update was applied in the first place, leaving the system vulnerable to recurrence without proper process enforcement.

  • Contact the software vendor to request a patch for the crash.

    Why it's wrong here

    Contacting the software vendor prematurely shifts responsibility for what is primarily an internal process failure. The immediate problem is an unauthorized change within the organization's control, not necessarily a defect requiring a vendor patch. Escalating to the vendor before documenting and addressing the internal change management breach would bypass the necessary internal review and accountability steps, potentially leading to misdiagnosis or unnecessary external intervention without understanding the full context.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.