Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A junior technician performed a configuration change on a critical server without following the change management process. As a result, the server went offline for two hours. Which of the following BEST describes the purpose of a change management policy?

⚠ Common exam trap

Many candidates confuse the purpose of change management with speed (A) or restriction (D), overlooking that its core goal is risk reduction through structured review and documentation, not just authorization or auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure changes are reviewed, approved, and documented to minimize risks

The change management policy ensures that all changes are reviewed, approved, and documented before implementation, which minimizes the risk of unplanned outages like the one caused by the junior technician. By following a structured process, potential impacts are assessed, rollback plans are prepared, and stakeholders are informed, preventing unauthorized or poorly planned changes from disrupting critical services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To allow technicians to make changes quickly to resolve critical issues

    Why it's wrong here

    While temporarily enabling faster fixes may seem beneficial, change management deliberately prioritizes controlled, risk-assessed processes over raw speed. An unapproved or untested change made in haste can cause outages or security issues, so even critical incidents normally require an emergency change process with rapid but still-documented review. The goal is not to slow technicians down, but to ensure that urgency does not override safety and accountability.

  • ✓

    To ensure changes are reviewed, approved, and documented to minimize risks

    Why this is correct

    This is the core purpose of change management: a structured lifecycle where proposed changes are evaluated for potential impact, approved by an appropriate authority, implemented with a defined rollback plan, and documented for future reference. The review and approval steps catch configuration errors before they reach production, and documentation provides an audit trail and a baseline for troubleshooting. Ultimately, this minimizes the risk of service disruptions, security vulnerabilities, and unauthorized modifications.

  • ✗

    To track every single configuration change for auditing purposes only

    Why it's wrong here

    Auditing and record-keeping are important outputs of change management, but they are not the primary driver. The main objective is to reduce operational risk and maintain system stability by ensuring that every meaningful change is evaluated and approved before it is applied. Mandating documentation for every single configuration change, including trivial or routine ones, would create overhead without commensurate risk reduction, and it overlooks that the process is about proactive control, not just retrospective tracking.

  • ✗

    To restrict who can perform any changes on production servers

    Why it's wrong here

    Change management does define who can authorize and perform changes, but its scope is far broader than access restriction. It involves coordinating impact assessments, change scheduling, peer reviews, testing, and communication with stakeholders, as well as defining emergency approval paths. Restricting technician permissions is a separate security control (least privilege / RBAC); change management is about managing how and why changes occur, not merely blocking who can make them.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.