220-1102 Operational Procedures Practice Question
A technician needs to apply a critical security patch to a production server that cannot be shut down during business hours. According to change management best practices, which step must be completed before implementing this emergency change?
⚠ Common exam trap
Watch out — candidates often confuse operational urgency with procedural necessity, assuming that because a patch is critical, they can skip the formal approval step and jump directly to technical actions like backups or notifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit a change request and obtain formal approval
In change management best practices, any change—including emergency patches—must follow a formal process. Option C is correct because submitting a change request and obtaining formal approval ensures that the change is documented, risks are assessed, and stakeholders are informed, even when the change is urgent. This step is critical to maintain audit trails and prevent unauthorized modifications that could lead to service disruption or security breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify all users that a reboot will occur
Why it's wrong here
While user notification is a communication best practice, it does not authorize the change or provide a governance gate. The change management process mandates that a formal approval—typically from the Change Advisory Board—be secured before any implementation on a production server. Notifying users about a reboot is an operational courtesy that occurs after the change is approved and scheduled, not a prerequisite that permits deployment. Performing the patch without approval, even with advance notice, would be an unauthorized change.
- ✗
Create a full backup of the server
Why it's wrong here
A full backup is a critical rollback contingency, allowing restoration if the security patch corrupts the system or introduces a regression. However, creating a backup is a technical preparatory action that must be documented in the change plan, not a formal authorization step. The change management process requires approval before any modification to production; a backup alone does not grant permission to deploy the patch. Without CAB approval, the backup is simply an unapproved preparatory activity and the subsequent deployment remains a violation of change management policy.
- ✓
Submit a change request and obtain formal approval
Why this is correct
A critical security patch still requires a formal change request and approval from the designated authority, such as the Change Advisory Board, even under emergency conditions. The process is expedited—often through an emergency CAB session or a pre-approved emergency change window—but the approval gate is never bypassed. This step formally documents the patch's risk assessment, rollback plan, and implementation window, ensuring accountability and compliance with organizational policy. Obtaining approval before deployment is the only non-negotiable step in this scenario.
- ✗
Test the patch on a non-production system
Why it's wrong here
Testing on a non-production system is a best practice that validates patch stability, but it is not a mandatory prerequisite for an emergency patch, particularly when the vulnerability is being actively exploited. In a zero-day scenario, the organization may receive approval to deploy immediately, accepting the risk of insufficient testing to mitigate the immediate security threat. Testing, when possible, becomes part of the change plan's risk assessment but does not substitute for the formal approval step required by change management. Thus, while ideal, testing is not the step that must be completed before implementation.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.