Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A company wants to ensure that all changes to network infrastructure are reviewed and approved. A technician finds a critical vulnerability that needs immediate patching. What should the technician do?

⚠ Common exam trap

A common mix-up: candidates choose Option A, thinking that patching a critical vulnerability is more important than following procedure, but the exam emphasizes that even urgent changes must go through a documented emergency change process to maintain accountability and prevent unauthorized changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit an emergency change request

When a critical vulnerability is discovered, the standard change management process should be bypassed via an emergency change request to apply the patch immediately. This aligns with the CompTIA A+ 220-1102 objective on operational procedures, which requires balancing security urgency with formal approval to minimize risk. The technician must still document the change after the fact to maintain an audit trail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the patch and document later

    Why it's wrong here

    Applying the patch without prior approval violates change management policy, as the potential impact, rollback procedure, and compatibility with the existing infrastructure are not assessed before implementation. Documenting the change after the fact does not restore the lost opportunity to prevent a service outage or unforeseen side effects. Moreover, in a regulated or audited environment, an undocumented unauthorized change can be treated as a finding that undermines the integrity of the entire change management process.

  • ✓

    Submit an emergency change request

    Why this is correct

    An emergency change request is the appropriate, controlled pathway when a patch is critical to address a vulnerability or failure. It bypasses the normal change advisory board (CAB) timetables but still requires justification, risk assessment, and documented back-out procedures, often with a post-change review. This ensures that urgency does not eliminate oversight, and the technician gains formal authorization in a matter of hours rather than days.

  • ✗

    Wait for the next scheduled change window

    Why it's wrong here

    Waiting for the next scheduled change window leaves the network exposed to the vulnerability the patch addresses, contradicting the urgency of the scenario. While a standard change window is suitable for routine updates, an emergency change is explicitly designed for high-impact anomalies like security hotfixes. The delay also complicates eventual deployment because the change is no longer a planned improvement and may be implemented under pressure, increasing the chance of human error.

  • ✗

    Inform the users and proceed

    Why it's wrong here

    Informing users about an intended infrastructure change is an informal communication, not a substitute for authorization from the change approval authority. Without a documented change request, there are no defined success criteria, rollback steps, or compatibility checks, so the technician lacks a formal safety net if the patch fails. Additionally, users are typically not the stakeholder accountable for technical risk; governance requires submission through the change management process, which includes technical review and scheduling coordination.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.