Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician completes an approved firmware update on a network switch. After the update, the switch functions correctly, but the management interface now requires HTTPS instead of HTTP. The change plan only mentioned updating firmware to patch a security vulnerability. According to change management best practices, what should the technician do NEXT?

⚠ Common exam trap

A common mix-up: candidates assume any security improvement is automatically acceptable without formal documentation, but CompTIA 220-1102 emphasizes that change management requires all changes—even beneficial ones—to be recorded and approved by the CAB to maintain process integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the HTTPS change and submit a post-change report to the CAB

Change management best practices require that any deviation from the approved change plan—even an unintended but beneficial one like the switch from HTTP to HTTPS—must be documented and reported to the Change Advisory Board (CAB). The technician should not assume the change is acceptable without formal approval; the CAB must review the security improvement and update the change record accordingly. This ensures auditability and compliance with organizational policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Revert the firmware to the previous version to restore HTTP access

    Why it's wrong here

    Rolling back the firmware is a disproportionate and unauthorized response to an HTTP access change. The firmware update itself succeeded, and the switch is functioning normally; the HTTP/HTTPS setting is a separate configuration item that was altered, not a fault caused by the firmware. Reverting the firmware would reintroduce the exact vulnerabilities the approved update was meant to patch, require a reboot that could disrupt network traffic, and still would not restore HTTP because the configuration change would remain. A firmware rollback is reserved for a failed update or severe regression, not for an unapproved configuration discovery.

  • ✓

    Document the HTTPS change and submit a post-change report to the CAB

    Why this is correct

    This is the correct response because change management procedures require that every actual change to a production network device, including unintended or incidental changes, be documented and submitted for review. The post-change report should describe the discovered HTTPS configuration, why it differs from the approved plan, and the potential impact on services and security. Submitting this to the CAB (Change Advisory Board) lets the board formally evaluate the change, accept it retroactively, or direct a controlled reversion—while preserving audit trail and accountability. This aligns with ITIL-based change management and prevents undocumented configuration drift.

  • ✗

    Leave the configuration as is since HTTPS improves security

    Why it's wrong here

    While HTTPS is objectively more secure than HTTP, the technician does not have the authority to permanently alter the switch configuration beyond the scope of the approved firmware update. Leaving the change undocumented violates the organization's change management policy, which exists to ensure all changes are reviewed for unintended operational or security impacts—even positive-looking ones. An undocumented HTTPS migration could also break integrations or management scripts that expect HTTP, causing support issues that are impossible to diagnose without a change record. The only correct way to keep the HTTPS improvement is to document it and obtain post-change approval from the CAB.

  • ✗

    Disable HTTPS and configure the switch to use HTTP only

    Why it's wrong here

    Forcing the switch back to HTTP-only is the opposite of a security best practice and would expose management traffic to plaintext credentials over the network. Moreover, this action is just as unauthorized as the original HTTPS change—any modification to the configuration, including a reversion, must go through change management. The technician cannot unilaterally decide to alter the network's security posture, especially after an approved firmware update that likely aimed to strengthen security. The proper action is to notify the CAB and let them decide the final configuration, not to perform another unapproved change that introduces a new security risk.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.