Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: During a software deployment, a technician must…

During a software deployment, a technician must explain to a non-technical manager why a critical security update requires an immediate reboot of all workstations, even though it interrupts work. The manager is concerned about productivity loss. How should the technician communicate this?

⚠ Common exam trap

CompTIA often tests the candidate's ability to prioritize security over convenience and to communicate technical risks in business terms, so the trap here is choosing a technically correct but poorly communicated answer (like B or C) that fails to address the manager's legitimate productivity concerns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

"The update fixes a vulnerability that could let attackers steal company data. A reboot is required to apply it. The risk of a breach outweighs the short downtime."

It directly addresses the manager's concern about productivity loss by clearly explaining the security risk (data theft via an unpatched vulnerability) and why the reboot is necessary to apply the update. This approach uses risk-benefit language that a non-technical manager can understand, aligning with the CompTIA A+ objective of communicating technical requirements to stakeholders in business terms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • "The update fixes a vulnerability that could let attackers steal company data. A reboot is required to apply it. The risk of a breach outweighs the short downtime."

    Why this is correct

    This response effectively communicates the critical nature of the update by explaining the direct business impact: preventing data theft due to a vulnerability. It clearly states the technical requirement (reboot) and provides a strong justification by weighing the risk of a security breach against the short operational downtime. This approach demonstrates a technician's ability to translate technical issues into understandable business terms, fostering informed decision-making and cooperation from non-technical stakeholders.

  • "Just schedule the reboot for after hours and it won't affect productivity."

    Why it's wrong here

    While scheduling reboots after hours is often a best practice to minimize disruption, this response fails to convey the critical nature or urgency of the update. It does not explain *why* the update is necessary or the potential severe consequences of delaying it, such as a security breach. This approach lacks transparency and does not empower the manager to understand the importance of the task, potentially leading to a lack of prioritization or understanding of the associated risks.

  • "It's IT policy. We have to do this. Please inform your team."

    Why it's wrong here

    This response is dismissive and provides no technical or business context for the required action. Simply citing "IT policy" without explaining the underlying reason (e.g., security, compliance, system stability) can lead to resentment and a lack of cooperation from other departments. It fails to educate the manager about the importance of the update, treating them as merely an order-taker rather than a partner in maintaining system integrity and security.

  • "The update is mandatory, but you can delay it for a week if needed."

    Why it's wrong here

    Offering to delay a "mandatory" update, especially one implied to be critical (as per the question context of a security vulnerability), demonstrates poor judgment and a lack of understanding of risk management. Delaying security patches can leave systems vulnerable to exploitation for an extended period, significantly increasing the likelihood of a data breach or system compromise. This approach prioritizes convenience over critical security posture, which is unprofessional and potentially catastrophic for the organization.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.