mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A help desk technician receives a complaint that…
A help desk technician receives a complaint that a user’s custom software application stopped working after a Windows update was installed automatically overnight. The technician checks the system and finds the update is not in the approved change log. What should the technician do next?
⚠ Common exam trap
Test-takers frequently think restoring functionality (Option A) or preventing future updates (Option D) is the priority, but CompTIA emphasizes that following change management documentation and incident reporting is the correct first step, not just fixing the symptom.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roll back the Windows update and document the incident
The update was installed without authorization (not in the approved change log), violating change management policy. The technician should immediately roll back the update to restore application functionality and then document the incident to ensure proper change control procedures are followed. This aligns with the CompTIA A+ change management process: identify the unauthorized change, reverse it, and report it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reinstall the custom application immediately
Why it's wrong here
Reinstalling the custom application immediately is an ineffective first step because the issue likely stems from the Windows update altering the application's operating environment, not from the application itself being corrupted. The update could have modified system dependencies, libraries, or configuration files that the custom application relies upon, making a simple reinstall insufficient. This action also fails to address the root cause, which is the unauthorized system change, and does not restore the previous working state.
- ✓
Roll back the Windows update and document the incident
Why this is correct
Rolling back the Windows update is the most direct and efficient method to restore the system to its last known good configuration, thereby immediately resolving the application's functionality issue caused by the unauthorized change. This action directly addresses the identified root cause. Concurrently, documenting the incident is crucial for maintaining a comprehensive audit trail, identifying the source of the unauthorized update, and implementing preventative measures to ensure future compliance with change management policies.
- ✗
Leave the update in place and submit a new change request for the application
Why it's wrong here
Leaving the unauthorized Windows update in place while the custom application remains non-functional prolongs user downtime and negatively impacts productivity, which is unacceptable in an incident response scenario. Submitting a new change request for the application implies a lengthy development and testing cycle to adapt the application to the new, potentially problematic, system state. This approach prioritizes a long-term, reactive solution over immediate service restoration and fails to address the immediate operational disruption caused by the unauthorized system modification.
- ✗
Disable Windows Update on the workstation permanently
Why it's wrong here
Permanently disabling Windows Update on the workstation is an extreme and highly insecure measure that introduces significant security vulnerabilities by preventing the system from receiving critical security patches and bug fixes. This action would leave the system susceptible to known exploits and malware, directly contradicting fundamental cybersecurity best practices and organizational security policies. It is an irresponsible response that creates a much larger, systemic problem rather than properly resolving the unauthorized change through incident management.
Go deeper
Related to this question
Learn chapter
Windows Editions and Features
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.