Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is tasked with deploying a critical security patch to all workstations in the organization. The patch addresses a remote code execution vulnerability. The technician has already tested the patch on a non-production machine and it installed successfully. According to standard change management procedures, what should the technician do BEFORE deploying the patch to production workstations?

⚠ Common exam trap

A common mix-up: candidates assume successful testing on a non-production machine is sufficient to proceed directly to deployment, overlooking the mandatory change management step of CAB approval that governs all production changes, even for critical security patches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit a change request to the Change Advisory Board (CAB) for approval

B is correct because standard change management procedures require that any change with potential impact on production systems, such as a security patch addressing a remote code execution vulnerability, must be formally approved by the Change Advisory Board (CAB) before deployment. Even though the patch was tested successfully on a non-production machine, the CAB must review the change for risk, rollback plans, and scheduling to ensure it aligns with organizational policies and minimizes disruption. Skipping this step violates ITIL-based change management frameworks and could lead to unapproved changes that introduce instability or compliance issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a full backup of all production workstations

    Why it's wrong here

    Creating backups is a prudent safety measure but is not the mandatory first step according to change management process. The technician should first obtain approval, and then ensure backups are taken as part of the implementation plan.

  • ✓

    Submit a change request to the Change Advisory Board (CAB) for approval

    Why this is correct

    Under formal change management, the mandatory first action for any production-affecting change, including a critical security patch, is to submit a change request so the CAB can perform a structured risk/impact review and formally authorize the deployment. The CAB evaluates factors such as potential system conflicts, resource availability, and the adequacy of the proposed rollback plan; attempting to bypass this approval step violates organizational policy and may lead to the change being rejected after the fact. Even urgent patches must follow the governance process, as the CAB serves to coordinate changes across all systems and prevent unintended downtime.

  • ✗

    Schedule the patch deployment during the next maintenance window

    Why it's wrong here

    Selecting a maintenance window is an implementation-planning activity that cannot be validly performed until the CAB has approved the change request itself. Without formal authorization, scheduling a deployment is premature because the window allocation may conflict with other approved maintenance activities, and the change could be cancelled or rescheduled once the CAB reviews its true impact. The correct sequence under change management is to obtain approval first, then determine the maintenance window in accordance with the approved change schedule.

  • ✗

    Document the rollback plan in case the patch causes issues

    Why it's wrong here

    Documenting a rollback plan is an important component of a change request, but it is done within the change request itself. The final step before deployment is to receive approval, not just to have a rollback plan.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.