220-1102 Operational Procedures Practice Question
A technician needs to apply a non-critical security patch to a production web server. According to change management best practices, what should the technician do FIRST?
⚠ Common exam trap
The 220-1102 exam often tests the misconception that testing or scheduling should be the first step, but the exam emphasizes that formal authorization via a change request must precede any technical action, even for low-risk changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a change request and submit it for approval
According to change management best practices, any change to a production system—including applying a non-critical security patch—must follow a formal process. The first step is to create a change request and submit it for approval, ensuring the change is reviewed, risk-assessed, and authorized before implementation. This aligns with the CompTIA A+ 220-1102 objective on operational procedures, which emphasizes that even non-critical patches require documented approval to maintain system stability and audit trails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately to keep the server secure
Why it's wrong here
Applying the patch immediately violates change management policy for a non-urgent change. Even though the patch addresses security, it poses risks of unplanned downtime, configuration conflicts, and an absent rollback plan if issues arise. An emergency change process is only justified for critical threats, whereas a non-critical patch must go through standard review and approval prior to installation.
- ✗
Schedule the patch to be applied during the next maintenance window
Why it's wrong here
Scheduling the patch for a maintenance window is the right implementation step, but it is premature before the change request has been approved. The request must be submitted and reviewed first; the CAB determines whether the change is authorized and then assigns an appropriate implementation window. Proceeding to schedule without approval skips the risk assessment and leaves the change undocumented and unauthorized.
- ✓
Create a change request and submit it for approval
Why this is correct
Creating a formal change request and submitting it to the CAB is the mandatory first action for any non-critical change. The request must document the patch contents, affected systems, risk assessment, testing plan, and rollback procedure so the board can make an informed decision. Approval from the CAB authorizes implementation and ensures proper scheduling, communication, and auditability. Without this step, no subsequent work is permitted.
- ✗
Test the patch on a non-production server before applying to production
Why it's wrong here
Testing the patch on a non-production server is an essential validation activity, but it cannot occur before approval is granted. The test plan should be embedded within the change request itself, and the CAB's approval authorizes both the testing and the eventual production deployment. Unofficial pre-testing may alter the non-production environment with unapproved changes and fails to provide the documented evidence needed for formal review.
Go deeper
Related to this question
Learn chapter
macOS System Preferences and Settings
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician needs to apply a critical security patch to a production web server. The patch is known to require a service restart, which will cause a brief outage. According to change management best practices, what is the FIRST step the technician should take?
easy- A.Install the patch immediately to mitigate the security vulnerability
- ✓ B.Submit a change request for review and approval
- C.Notify all users that the server will be unavailable
- D.Test the patch in a lab environment first
Why B: The correct first step is to submit a change request for review and approval. Change management best practices require that any change with a potential service impact—such as a security patch that forces a restart and causes a brief outage—be formally documented, reviewed, and approved by a change advisory board (CAB) before implementation. This ensures that risks are assessed, rollback plans are prepared, and stakeholders are informed, preventing unauthorized downtime in a production environment.
Variation 2. A technician needs to apply a critical security patch to a server that hosts a legacy application. The patch is known to cause a brief service interruption during installation. According to change management best practices, which of the following should the technician do FIRST before installing the patch?
medium- A.Install the patch immediately to minimize security exposure, then document the change afterwards.
- ✓ B.Submit a change request to the change control board and develop a backout plan.
- C.Schedule the installation during off-peak hours and run the patch without prior approval.
- D.Test the patch on a non-production server and then apply it to the production server without filing a change request.
Why B: Change management best practices require that any change with a known service interruption, such as applying a critical security patch, must first be submitted as a change request to the change control board (CCB). This ensures proper review, scheduling, and risk assessment. Developing a backout plan is also essential to restore the server to its previous state if the patch fails or causes unexpected issues, minimizing downtime for the legacy application.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.