220-1102 Operational Procedures Practice Question
A technician has completed an emergency change to restore a critical server after a security breach. The change was not pre-approved by the Change Advisory Board (CAB) due to the urgency. According to change management best practices, what should the technician do NEXT?
⚠ Common exam trap
Many exam-takers confuse 'emergency change' with 'no approval needed,' but CompTIA tests that even emergency changes require retrospective CAB approval to maintain change management integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the change and submit it for retrospective approval.
Per ITIL change management best practices, emergency changes bypass pre-approval but must be documented and submitted for retrospective approval to the CAB after implementation. This ensures traceability, accountability, and compliance, even in urgent scenarios like a security breach recovery. The technician must complete the change record and request post-facto authorization to close the loop.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Submit a post-implementation review within 30 days.
Why it's wrong here
While a review should occur, it should happen much sooner than 30 days; the normal expectation is within a few days or a week at most. Delaying the review could cause issues to go unnoticed.
- ✓
Document the change and submit it for retrospective approval.
Why this is correct
Emergency changes are designed to bypass the pre-approval step of the normal change management process, but they do not waive the need for accountability. Documenting the change in the change management system and submitting it for retrospective approval allows the CAB to review the action, assess its effectiveness, and ensure it did not introduce unintended risks. This formal after-the-fact approval creates an audit trail and fulfills governance requirements while acknowledging the urgency of the situation.
- ✗
Revert the change and wait for CAB approval.
Why it's wrong here
Reverting a successful emergency change would undo the fix that restored service, likely causing the original critical incident to recur and extending downtime unnecessarily. Emergency change policies explicitly permit a change to be implemented without prior CAB approval, so there is no requirement to revert the change while waiting for authorization. Instead, the change should remain in place, and the CAB can conduct its review retrospectively, focusing on lessons learned rather than delaying the resolution.
- ✗
Notify the CAB that no approval is needed for emergency changes.
Why it's wrong here
Emergency changes are still subject to CAB oversight; the only difference is the timing of the approval relative to the implementation. Notifying the CAB that no approval is needed is factually incorrect and would violate change management procedures, potentially exposing the organization to unauthorized changes, compliance issues, and lack of a proper audit record. The change must still be formally logged and submitted for retrospective approval to ensure it is reviewed, documented, and accepted by the CAB after the fact.
Go deeper
Related to this question
Learn chapter
Windows Recovery Tools
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.