mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is documenting a configuration…
A technician is documenting a configuration change to a firewall rule that allows remote access for a new employee. The technician must ensure the documentation is clear for future audits. Which of the following is the most critical piece of information to include?
⚠ Common exam trap
CompTIA often tests the principle that operational details (who, when, where) are less critical than the business justification in change management documentation, tempting candidates to choose the most concrete or easily recorded detail instead of the most audit-relevant one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The business justification for the rule.
Change management documentation must include the business justification to demonstrate that the change was authorized and necessary. Without a clear reason, auditors cannot verify that the firewall rule complies with organizational security policy or regulatory requirements. The business justification provides the context needed to distinguish legitimate changes from unauthorized or malicious modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The exact date and time the rule was added.
Why it's wrong here
While crucial for auditing and tracking changes within a comprehensive change management system, the exact timestamp primarily indicates *when* a configuration modification occurred, not *why*. Without the underlying business rationale, simply knowing the date and time provides insufficient context for understanding the necessity or impact of the change, especially during future reviews, troubleshooting, or compliance audits. It documents the timing, not the purpose.
- ✗
The IP address of the new employee's remote location.
Why it's wrong here
The specific IP address of a remote location is a technical detail that describes *what* was configured (e.g., a firewall rule's source or destination). However, it fails to articulate the *purpose* or *reason* behind implementing that configuration change. Documenting only the IP address without the business context makes it difficult to ascertain the rule's intent, justify its continued existence, or understand its role in the overall network security posture.
- ✓
The business justification for the rule.
Why this is correct
The business justification provides the critical "why" behind any configuration change, linking the technical action directly to an organizational need, policy, or problem resolution. This explanation is paramount for audit compliance, demonstrating adherence to security policies, and facilitating future reviews or troubleshooting by clearly articulating the intended purpose and expected outcome of the modification. It ensures the change aligns with strategic objectives and operational requirements.
- ✗
The name of the technician who made the change.
Why it's wrong here
Identifying the technician responsible for a configuration change is vital for accountability and tracking within a robust change management process. However, knowing *who* made the change does not explain *why* the change was necessary or what business problem it aimed to solve. While useful for follow-up questions, performance tracking, or incident response, it lacks the contextual depth required for comprehensive documentation of the change's underlying purpose and impact.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.