220-1102 Operational Procedures Practice Question
A network administrator discovers a critical security vulnerability in a production firewall that could allow external attackers to bypass authentication. The administrator applies a configuration change to fix the vulnerability immediately, without waiting for the next Change Advisory Board (CAB) meeting. After the change is applied and verified to be successful, what should the administrator do NEXT according to change management best practices?
⚠ Common exam trap
Many candidates assume any emergency change must be reverted if not pre-approved, but CompTIA tests the understanding that emergency changes are allowed for critical security fixes and the follow-up action is a formal post-implementation review with the CAB, not a rollback.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule a post-implementation review with the CAB as soon as possible
Change management best practices require that even emergency changes—those made without prior CAB approval due to an immediate security threat—must be followed by a post-implementation review with the CAB as soon as possible. This ensures the change is formally documented, approved retroactively, and lessons learned are captured. The administrator has already applied and verified the fix, so the next step is to schedule that review to maintain compliance with the change management process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send an email to the security team informing them of the change
Why it's wrong here
An email to the security team is an informal notification that does not create an auditable record or satisfy the organization's change management policy. The CAB must formally review emergency changes through a structured process, including risk assessment and approval, which a simple email cannot provide. Without CAB involvement, the change remains unapproved and could violate compliance requirements.
- ✗
Document the change in the server's local log file only
Why it's wrong here
Recording the change solely in the server's local log file fails to integrate it into the change management system where risk, rollback plans, and approvals are documented. Local logs are typically system-generated and lack the required context for a formal post-implementation review, such as the reason for the change and its impact analysis. This approach would leave the change undocumented from a governance perspective, making it impossible for the CAB to properly evaluate.
- ✓
Schedule a post-implementation review with the CAB as soon as possible
Why this is correct
A post-implementation review with the CAB is the correct follow-up to an emergency change because it formalizes the authorization retroactively and allows the CAB to assess the change's effectiveness and any unintended consequences. This review also serves as a learning opportunity to improve future emergency procedures and ensures that the change aligns with security policies and business objectives. It is the standard change management practice for emergency changes that bypass the normal approval workflow.
- ✗
Revert the change and wait for CAB approval before reapplying
Why it's wrong here
Reverting a critical security fix would re-expose the system to the vulnerability that necessitated the emergency change, potentially leading to a security breach. The change was justified as an emergency, so the priority is to maintain the secure state while pursuing a retrospective review rather than undoing the fix. Waiting for CAB approval before reapplying would create a period of unnecessary risk and would not align with the principle of preserving system security during the change process.
Go deeper
Related to this question
Learn chapter
Certificate Management for A+
Key term
Lessons learned
Lessons learned is the process of capturing, analyzing, and documenting knowledge gained from past incidents or projects to improve future security operations and prevent recurrence of problems.
Key term
Power-on Self-test
The Power-on Self-test (POST) is a diagnostic process a computer runs immediately when you turn it on to check that essential hardware components are working correctly before loading the operating system.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.