220-1102 Operational Procedures Practice Question
A technician needs to apply a critical security patch to a production web server to stop an active exploit. The standard change window is not for another week, but the patch has already been approved by the Change Advisory Board (CAB). What should the technician do according to change management best practices?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit an emergency change request for expedited implementation
When a change is needed urgently, an emergency change request should be submitted to expedite the process outside the standard window. Even with CAB approval, proceeding outside the standard window without emergency authorization violates change management procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately since it is already approved
Why it's wrong here
Applying an already-approved patch immediately ignores the change management schedule: approval covers the change itself, not the timing, and production implementations must still occur within an approved maintenance window. Bypassing the window without invoking emergency procedures also forfeits the mandated rollback plan and impact assessment, potentially causing unplanned downtime and audit violations if the patch misbehaves.
- ✗
Wait for the next standard change window to apply the patch
Why it's wrong here
Waiting for the next standard change window is unacceptable because the vulnerability is actively being exploited, leaving the web server exposed for hours or days. Standard windows are optimized for routine, low-risk changes, not for urgent security threats; delaying treatment of a critical zero-day or actively exploited CVE increases the chance of a data breach or defacement. The change management policy itself provides an emergency path for exactly this situation, so using it is the speed and control compromise.
- ✓
Submit an emergency change request for expedited implementation
Why this is correct
Submitting an emergency change request is the correct response because it fast-tracks the patch through a condensed approval process—often an on-call CAB or single authorized approver—while still documenting the change, testing, and rollback steps. This maintains governance and accountability during a critical incident, unlike ad-hoc patching, and is the explicitly designed mechanism for out-of-cycle, high-priority production changes.
- ✗
Contact the vendor for a newer version of the patch that can wait
Why it's wrong here
Contacting the vendor for a newer patch is an unhelpful detour: the existing patch is already the critical fix needed, and waiting for a hypothetical newer version delays protection during an ongoing exploit. The vendor may not have a newer build available or validated, and the proactive step is to deploy the current emergency patch through the emergency change process. Vendor follow-up could happen later to request future hardening, but it must not take priority over immediate mitigation.
Go deeper
Related to this question
Learn chapter
SOHO Router Security Configuration
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician needs to apply a critical security patch to a production server that cannot be shut down during business hours. According to change management best practices, which step must be completed before implementing this emergency change?
medium- A.Notify all users that a reboot will occur
- B.Create a full backup of the server
- ✓ C.Submit a change request and obtain formal approval
- D.Test the patch on a non-production system
Why C: In change management best practices, any change—including emergency patches—must follow a formal process. Option C is correct because submitting a change request and obtaining formal approval ensures that the change is documented, risks are assessed, and stakeholders are informed, even when the change is urgent. This step is critical to maintain audit trails and prevent unauthorized modifications that could lead to service disruption or security breaches.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.