220-1102 Operational Procedures Practice Question
A technician needs to apply a critical security patch to a production web server. The patch is known to require a service restart, which will cause a brief outage. According to change management best practices, what is the FIRST step the technician should take?
⚠ Common exam trap
It's easy for candidates to choose 'Test the patch in a lab environment first' (Option D) because they focus on technical validation, but the exam emphasizes that change management procedural steps—specifically submitting a change request—take precedence over any technical action in a production environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit a change request for review and approval
The correct first step is to submit a change request for review and approval. Change management best practices require that any change with a potential service impact—such as a security patch that forces a restart and causes a brief outage—be formally documented, reviewed, and approved by a change advisory board (CAB) before implementation. This ensures that risks are assessed, rollback plans are prepared, and stakeholders are informed, preventing unauthorized downtime in a production environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the patch immediately to mitigate the security vulnerability
Why it's wrong here
Installing a patch immediately bypasses the formal change management process, exposing the production web server to unapproved modifications that can introduce regressions or configuration drift. Without a change request, there is no rollback plan, no stakeholder sign-off, and no scheduled maintenance window, so an unexpected incompatibility could violate availability SLAs. Even for security vulnerabilities, the correct path is to escalate urgency through an emergency change request rather than skipping authorization entirely.
- ✓
Submit a change request for review and approval
Why this is correct
Submitting a change request is the mandatory first step because it forces impact analysis, resource planning, and a defined maintenance window before touching a production web server. The change advisory board (CAB) reviews risk, approves or rejects the change, and ensures that rollback procedures are documented and tested. This formal record also enables post-implementation review and provides accountability, which is essential for regulated or high-availability environments.
- ✗
Notify all users that the server will be unavailable
Why it's wrong here
Notifying users prematurely is counterproductive because, at the very start, the scope, duration, and exact impact of the maintenance window have not yet been defined. Any notification sent before approval would either be too vague to act on or risk being factually wrong if the change is modified during review. User communication is a downstream artifact of an approved change schedule, not a substitute for the authorization that determines those details.
- ✗
Test the patch in a lab environment first
Why it's wrong here
Testing the patch in a lab is a valuable implementation step, but it is not a substitute for submitting a change request and cannot be the first action because it does not establish the authority to deploy. A lab test also cannot fully replicate production dependencies, network paths, or load conditions, so it must be paired with an approved plan that includes rollback and communication. In practice, testing happens after the change request is approved, as part of the implementation plan.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.