Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A technician needs to deploy a critical security patch to a production file server. The patch has already been tested successfully in a lab environment. According to standard change management best practices, what must the technician do before deploying the patch to production?

⚠ Common exam trap

Candidates often assume a successful lab test eliminates the need for formal change approval, but CompTIA emphasizes that production changes always require CAB authorization regardless of prior testing results.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit a change request and obtain approval from the Change Advisory Board

Even though the patch was tested successfully in a lab, standard change management best practices require a formal change request and approval from the Change Advisory Board (CAB) before deploying to a production environment. This ensures that the deployment is reviewed for potential risks, conflicts with existing configurations, and rollback procedures, minimizing the chance of unplanned downtime or data loss on the critical file server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately deploy the patch to minimize the vulnerability window

    Why it's wrong here

    Immediate deployment bypasses the formal change management process, which is mandatory even for critical patches to ensure proper risk assessment, scheduling, and communication. Unilateral action can lead to unplanned downtime, conflicts with other changes, and a lack of rollback readiness. Even emergency changes typically require an emergency change request and expedited CAB (or designated approver) sign-off, not unilateral action.

  • ✓

    Submit a change request and obtain approval from the Change Advisory Board

    Why this is correct

    Submitting a change request and obtaining Change Advisory Board (CAB) approval is the correct first step because it ensures the patch is reviewed for technical risk, deployment impact, and rollback plan before touching production infrastructure. The CAB coordinates cross-functional input, schedules the change to minimize business disruption, and documents the change for auditability and post-implementation review. This aligns with ITIL change management best practices for production changes.

  • ✗

    Deploy the patch only to non-business-critical servers first

    Why it's wrong here

    Deploying the patch only to non-business-critical servers first still involves making a production change without an approved change request, which violates change management policy regardless of the target environment or rollout order. Phased or pilot deployments are valid strategies, but they must be formally defined and approved within a change plan before any production system is modified. Additionally, prioritizing non-critical servers does not address the security vulnerability on the critical file server in a timely, controlled manner.

  • ✗

    Schedule the deployment during a maintenance window without additional approval

    Why it's wrong here

    Scheduling the deployment during a maintenance window does not negate the requirement for an approved change record; a maintenance window only defines a period of lower business impact, not an authorization to bypass change governance. Unapproved changes performed in a maintenance window remain unauthorized and undocumented, leading to configuration drift, audit deficiencies, and difficulty troubleshooting future incidents. Proper procedure requires a documented change request with CAB approval, even when the work is executed within a scheduled maintenance period.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician is tasked with deploying a critical security patch to all workstations in the organization. The patch addresses a remote code execution vulnerability. The technician has already tested the patch on a non-production machine and it installed successfully. According to standard change management procedures, what should the technician do BEFORE deploying the patch to production workstations?

medium
  • A.Create a full backup of all production workstations
  • ✓ B.Submit a change request to the Change Advisory Board (CAB) for approval
  • C.Schedule the patch deployment during the next maintenance window
  • D.Document the rollback plan in case the patch causes issues

Why B: B is correct because standard change management procedures require that any change with potential impact on production systems, such as a security patch addressing a remote code execution vulnerability, must be formally approved by the Change Advisory Board (CAB) before deployment. Even though the patch was tested successfully on a non-production machine, the CAB must review the change for risk, rollback plans, and scheduling to ensure it aligns with organizational policies and minimizes disruption. Skipping this step violates ITIL-based change management frameworks and could lead to unapproved changes that introduce instability or compliance issues.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.