220-1102 Operational Procedures Practice Question
After applying a scheduled security patch to a server and verifying its functionality, which change management step should the technician perform next?
⚠ Common exam trap
Watch out — candidates often confuse the post-implementation step with starting the next cycle (submitting a new request) or performing a task that should have been done earlier (documenting configuration), rather than recognizing that closing the current change request by logging results is the required procedural step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the change management log with the results
After applying a scheduled security patch and verifying functionality, the next step is to update the change management log with the results. This completes the change management process by documenting the patch's success, any issues encountered, and the verification outcome, ensuring an accurate audit trail for compliance and future reference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Update the change management log with the results
Why this is correct
Recording the patch outcome in the change management log is the mandatory closing step for any approved change. It captures whether the patch succeeded, any deviations from the plan, and observed post-implementation status, which is essential for audit compliance and for informing future troubleshooting or rollback decisions. Without this entry, the change remains 'open' and unverified.
- ✗
Submit a new change request for the next patch
Why it's wrong here
Submitting a new change request immediately after finishing the current patch is unnecessary because the next patch is a distinct change that requires its own planning, impact assessment, and approval window. Change management processes generally batch security patches into recurring maintenance cycles, so a new request would be created later as part of that scheduled cadence, not as a knee-jerk follow-up. Acting now would create redundant documentation and could bypass the required pre-implementation review.
- ✗
Document the server's current configuration
Why it's wrong here
Documenting the server's current configuration is a preparatory activity that should be performed before the patch is applied to establish a known baseline and rollback point. Performing it after the change would only record the post-patch state, which is already expected to differ from the approved plan and does not help close the change. The change management log already captures the necessary outcome details, making a separate configuration snapshot an unnecessary post-implementation action.
- ✗
Escalate the patch to the security team
Why it's wrong here
Escalating to the security team is reserved for exceptions, failures, or unexpected behavior such as a patch introducing vulnerabilities or failing to apply cleanly. After a routine scheduled patch that has been implemented successfully, there is no incident or decision point that warrants escalation; the change management log is the appropriate record of completion. Unnecessary escalation wastes security resources and can create false urgency around a normal maintenance operation.
Go deeper
Related to this question
Learn chapter
Change Management Process
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. After successfully replacing a failed hard drive and restoring data from backup, a technician verifies that the system is functioning normally. According to change management best practices, what should the technician do next?
easy- ✓ A.Submit a post-implementation report to the change advisory board.
- B.Dispose of the old hard drive in the regular trash.
- C.Close the help desk ticket without further documentation.
- D.Notify the user that the issue is resolved via email only.
Why A: According to change management best practices, after a change (such as replacing a failed hard drive and restoring data) has been implemented and verified, the technician must submit a post-implementation report to the Change Advisory Board (CAB). This report documents the outcome, any issues encountered, and confirms that the system is functioning normally, providing closure and accountability for the change.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.