220-1102 Operational Procedures Practice Question
A technician has identified a critical security vulnerability in a production web server that requires an immediate patch. The patch will cause a brief service interruption. According to change management best practices, which of the following is the BEST course of action?
⚠ Common exam trap
Test-takers frequently confuse 'immediate action' with 'no approval needed,' but CompTIA emphasizes that even emergency changes require authorized approval to maintain change management integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the IT manager and proceed with the patch after obtaining emergency verbal approval
Change management best practices require that emergency changes—such as patching a critical security vulnerability—follow an expedited approval process. Obtaining emergency verbal approval from the IT manager ensures the risk is mitigated quickly while still maintaining accountability and documentation. This balances the need for immediate remediation with the requirement for authorized oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately without approval to mitigate the risk
Why it's wrong here
Applying the patch without any approval violates the change management process, which exists to ensure accountability, assess risk, and coordinate communication. Even for emergency changes, an authorized approver (such as an IT manager) must give explicit permission, and the decision must be documented. Bypassing approval can lead to unintended system disruptions or security regressions without a clear owner to answer for the action.
- ✗
Submit a standard change request and wait for the next CAB meeting
Why it's wrong here
Submitting a standard change request and waiting for the next CAB meeting is too slow for a critical vulnerability, as the system remains exposed while the threat exists. Standard changes follow a prescribed schedule and involve formal review, which is appropriate for low-risk, routine work, not for urgent security patches. The correct approach is an emergency change that can be approved verbally by an authorized manager before the normal CAB cycle.
- ✓
Notify the IT manager and proceed with the patch after obtaining emergency verbal approval
Why this is correct
Notifying the IT manager and obtaining emergency verbal approval is the proper emergency change workflow, because it balances speed with accountability. The manager has authority to approve the change outside the normal CAB schedule, and the verbal approval can be documented and later ratified. This preserves audit trails while allowing immediate mitigation of the critical vulnerability, and it ensures that a designated person owns the decision.
- ✗
Schedule the patch for the next scheduled maintenance window
Why it's wrong here
Delaying the patch until the next scheduled maintenance window leaves a known critical vulnerability exploitable for an extended period, which can lead to data exposure or system compromise. A critical security patch should be treated as an emergency change, not a routine maintenance activity, because the risk of waiting outweighs the convenience of a planned downtime. Approval and deployment should happen immediately, with documentation completed after the fact.
Go deeper
Related to this question
Learn chapter
Windows Task Manager
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.