220-1102 Operational Procedures Practice Question
A company has a policy that all changes to network infrastructure must be approved by a supervisor before implementation. A technician notices a critical security vulnerability in a firewall that needs immediate patching. What should the technician do?
⚠ Common exam trap
Candidates often assume a security emergency justifies bypassing the change management process, but the exam emphasizes that policy must be followed even in urgent situations to maintain control and prevent unintended consequences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Follow the change management process and submit a request for approval
The company policy mandates that all changes to network infrastructure must be approved through the change management process. Even in a security emergency, bypassing the process can lead to unintended consequences, such as disrupting critical services or creating new vulnerabilities. Following the process ensures proper documentation, risk assessment, and coordination, which is essential for maintaining network stability and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement the patch immediately since it is a security emergency
Why it's wrong here
Implementing the patch immediately, even for a security emergency, bypasses the required change management workflow and violates the stated policy. Emergency changes still require an expedited submission, a risk assessment, a rollback plan, and formal approval—typically from an emergency change advisory board (CAB)—to prevent introducing unforeseen outages or incompatibilities. Without that review, the patch could conflict with existing network configurations or need a rollback that was never prepared.
- ✓
Follow the change management process and submit a request for approval
Why this is correct
Submitting a formal change request through the change management process is the only action that both complies with the policy and produces the necessary audit trail. The request will be evaluated for risk impact, a backout plan, and an appropriate change window, and it can be classified as an emergency to accelerate approval if needed. Even urgent security fixes must be documented and authorized to ensure the change is traceable and fully accountable.
- ✗
Notify the supervisor and await verbal approval before patching
Why it's wrong here
Relying solely on verbal approval from a supervisor gives you no documented, auditable authorization, which is a core requirement of standard change management procedures. A valid change requires a written record in the change management system that captures the approval, change details, and rollback strategy; verbal consent does not create that artifact. Additionally, a supervisor may not be an authorized approver for network infrastructure changes, meaning verbal permission could still fall short of policy.
- ✗
Send an email notification after patching
Why it's wrong here
Sending an email notification only after the patch has been applied is a reactive status update rather than a pre-implementation request for authorization, so it fails the policy's core requirement of prior approval. A post-change email cannot include the advance schedule, impact analysis, conflict checks, or change advisory board input that the change management process mandates. Moreover, without a prior change record, the organization has no formal documentation of the change's justification or a tested rollback plan.
Go deeper
Related to this question
Learn chapter
Change Management Process
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.