220-1102 Operational Procedures Practice Question
A technician is applying a critical security patch to a production database server during a scheduled maintenance window. The patch was tested in a lab environment and approved by the Change Advisory Board (CAB). During installation, the server prompts for an unexpected reboot. The change plan did not include a reboot, and the maintenance window is only 30 minutes long. According to change management best practices, what should the technician do FIRST?
⚠ Common exam trap
It's easy for candidates to assume a critical security patch justifies bypassing change control, but CompTIA tests that any unplanned action—even a reboot—requires CAB approval regardless of urgency or window constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stop the installation and contact the CAB for approval of the reboot.
Change management best practices require that any deviation from the approved change plan—such as an unexpected reboot—must be referred back to the Change Advisory Board (CAB) for approval before proceeding. Even though the patch is critical, the technician must not take unapproved actions that could cause unplanned downtime or data loss. The CAB is the only authority that can authorize a change to the plan, ensuring risk is properly assessed and communicated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proceed with the reboot since the patch is critical and the window is short.
Why it's wrong here
Proceeding with the reboot simply because the patch is critical and the window is short is a classic change-management violation. The urgency of a security patch does not override the need for pre-approved change approval, especially when the reboot was not part of the original plan. An unapproved reboot of a production database can interrupt active transactions, cause data corruption, and create an audit finding that may have regulatory consequences. The technician must not trade governance for speed; the correct action is to pause and seek formal approval from the Change Advisory Board (CAB).
- ✓
Stop the installation and contact the CAB for approval of the reboot.
Why this is correct
This is the only action that adheres to the approved change management framework. Stopping the installation before the unexpected reboot contains the risk and prevents an unauthorized modification to the production environment. The technician then contacts the CAB to explain the newly discovered reboot requirement, allowing the board to assess the impact, update the change record, and formally approve the reboot within or outside the original window. This preserves the integrity of the change process while still enabling the critical patch to be applied safely after the proper authorization.
- ✗
Reboot the server and document the change after completion.
Why it's wrong here
Rebooting the server and documenting the change after completion is an 'ask forgiveness, not permission' approach that bypasses the pre-approval requirement. Documentation after the fact does not retroactively legitimize an unauthorized action; it only creates a record of the violation. In a production database, an unapproved reboot can invalidate the change record for compliance audits and may be treated as a change management failure, even if no immediate damage occurs. The technician must obtain prior approval, not simply log the deviation after the event.
- ✗
Extend the maintenance window and continue with the reboot.
Why it's wrong here
Extending the maintenance window without authorization is a unilateral scope change, which is itself a violation of change management. Only the CAB has the authority to approve an extension of the maintenance window, because extending the window affects other scheduled operations, resource availability, and service-level agreements. An unapproved extension still leaves the reboot undocumented and unapproved, and it may also conflict with other change windows or create an overlap that increases operational risk. The correct course is to stop and request a formal CAB decision, not to unilaterally extend the timeline.
Go deeper
Related to this question
Learn chapter
Linux Package Management: apt and yum
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.