easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: A customer reports that their workstation is…
A customer reports that their workstation is running slowly after a recent group policy update. The change log indicates the update added new security settings. What is the most appropriate documentation step for the technician to take after resolving the issue?
⚠ Common exam trap
A common mix-up: candidates confuse the informal step of notifying the user (Option C) with the formal documentation requirement, or they may think that reverting the policy (Option D) is necessary without first verifying that the issue is fully resolved and documented.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Note the resolution in the change log and close the ticket.
After resolving the issue, the technician must document the resolution in the change log to maintain an accurate audit trail of changes and their outcomes. This aligns with change management best practices, ensuring that future technicians can see what was done to fix the problem and avoid repeating the same troubleshooting steps. Closing the ticket after documenting the resolution completes the incident management lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Note the resolution in the change log and close the ticket.
Why this is correct
Noting the resolution in the change log and closing the ticket is the correct procedure following a successful fix. This action ensures proper documentation of the incident, the steps taken to resolve it, and the final outcome, which is crucial for audit trails, knowledge management, and future troubleshooting. Closing the ticket formally marks the completion of the incident management process, moving it from an active to a resolved status.
- ✗
Delete the change log entry to avoid confusion.
Why it's wrong here
Deleting a change log entry is a critical violation of IT best practices and documentation standards. Change logs serve as an immutable historical record of all system modifications, troubleshooting efforts, and resolutions. Removing an entry compromises the integrity of the audit trail, prevents effective post-incident analysis, and eliminates valuable information that could be essential for diagnosing recurring issues or understanding system evolution.
- ✗
Send an email to the user explaining the fix.
Why it's wrong here
While communicating the fix to the user via email is a good customer service practice, it does not fulfill the formal documentation requirements of IT operations. An email is an informal, decentralized communication method that lacks the structured format, accessibility, and permanence of a dedicated change log or ticketing system entry. Relying solely on email for resolution documentation risks information loss and hinders the creation of a comprehensive, searchable knowledge base for the IT team.
- ✗
Create a new change request to revert the group policy.
Why it's wrong here
Creating a new change request to revert a group policy would only be necessary if the implemented fix involved a temporary policy adjustment that now needs to be undone, or if the resolution itself introduced a new problem requiring a rollback. In the context of a successfully resolved issue, the immediate and standard next step is to document the *current* resolution and close the existing ticket, not to initiate a new change request unless the resolution explicitly dictates a subsequent policy modification.
Visual reference
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.