220-1102 Operational Procedures Practice Question
A technician needs to apply a critical security patch to a server that hosts a legacy application. The patch is known to cause a brief service interruption during installation. According to change management best practices, which of the following should the technician do FIRST before installing the patch?
⚠ Common exam trap
Candidates often assume urgency (security patch) overrides process, but CompTIA emphasizes that even critical patches must follow change management procedures, including prior approval and a backout plan, to prevent unplanned downtime in production environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit a change request to the change control board and develop a backout plan.
Change management best practices require that any change with a known service interruption, such as applying a critical security patch, must first be submitted as a change request to the change control board (CCB). This ensures proper review, scheduling, and risk assessment. Developing a backout plan is also essential to restore the server to its previous state if the patch fails or causes unexpected issues, minimizing downtime for the legacy application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the patch immediately to minimize security exposure, then document the change afterwards.
Why it's wrong here
Installing the patch immediately and documenting afterwards bypasses the formal change approval process required for production systems. Change management mandates that all modifications be reviewed, tested, and scheduled before implementation, with the change record created upfront. Immediate action also neglects a backout plan, so if the patch breaks a legacy application, you have no pre-approved rollback procedure, risking prolonged downtime.
- ✓
Submit a change request to the change control board and develop a backout plan.
Why this is correct
Submitting a change request to the change control board (CCB) ensures the patch is formally assessed for risk, impact, and required testing before touching production. Developing a backout plan is equally critical because it provides a documented, step-by-step method to revert the server to its prior state if the patch fails or causes unforeseen issues. This approach complies with change management best practices and protects the legacy server's stability while still addressing the security vulnerability.
- ✗
Schedule the installation during off-peak hours and run the patch without prior approval.
Why it's wrong here
Choosing off-peak hours only addresses availability, not authorization; running the patch without prior approval still violates change management policy and may expose the organization to compliance and audit findings. Even a low-risk time window requires a change request containing the implementation steps, rollback procedure, and test evidence. Additionally, if the patch causes an outage during this unapproved window, the lack of a documented backout plan makes recovery chaotic and potentially prolonged.
- ✗
Test the patch on a non-production server and then apply it to the production server without filing a change request.
Why it's wrong here
Testing on a non-production server is prudent, but applying to production without filing a change request still bypasses the formal approval, communication, and change review process. A change request is needed not just to authorize the action, but to document results, define the deployment window, identify dependencies, and attach the backout plan. Even a successful test does not eliminate the need for change control, especially on a legacy system where production-only dependencies or hidden configuration drift can cause the patch to behave differently.
Go deeper
Related to this question
Learn chapter
Windows Services Management
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.