220-1102 Operational Procedures Practice Question
A technician has identified the need to update a critical server's operating system to meet new security compliance requirements. According to change management best practices, what is the NEXT step the technician should take after identifying the need?
⚠ Common exam trap
Many candidates confuse the sequence and think obtaining CAB approval is the immediate step, but the formal change request must be submitted first to document the need and initiate the approval workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit a formal change request
After identifying the need for a change, the correct next step per change management best practices is to submit a formal change request. This initiates the documented process, ensuring the change is properly reviewed, approved, and tracked before any implementation or planning occurs. Without a formal request, there is no record or authorization to proceed, which violates compliance and operational procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtain approval from the Change Advisory Board (CAB)
Why it's wrong here
Approval from the Change Advisory Board (CAB) is a downstream step that occurs only after a formal change request has been submitted, reviewed for impact, and technically evaluated. Since no change request exists yet, the CAB cannot convene or pronounce on the proposed update; the approval gate is triggered by the request document itself, not by recognizing the need. Therefore, seeking CAB approval as the immediate next action inverts the change management workflow.
- ✗
Implement the change
Why it's wrong here
Directly implementing the critical server update without formal authorization bypasses the entire change management process, leaving the change unrecorded, unassessed for technical or business risk, and without a tested fallback strategy. Unauthorized changes are a leading cause of unplanned outages because no one validates rollback procedures, dependency impacts, or maintenance windows in advance. Immediate implementation also strips stakeholders of the visibility needed to coordinate security patching with monitoring teams and other affected systems.
- ✗
Create a detailed backout plan
Why it's wrong here
A detailed backout plan belongs to the change-planning phase, which logically follows the submission and approval of the change request, not precedes it. Before you submit the request, you may have a rough idea of how to revert, but the full remediation steps—with validation tests and communication procedures—are normally developed and documented as part of the RFC once it enters the approval pipeline. Drafting the backout plan before filing the request puts the cart before the horse, since the change's scope and risk profile are not yet defined or agreed upon.
- ✓
Submit a formal change request
Why this is correct
Submitting a formal change request (RFC) is the correct first action because it officially documents the need, purpose, affected systems, implementation steps, and risk assessment of the proposed server update. This document creates the audit trail and serves as the basis for CAB review, scheduling, and later post-implementation review. By filing the RFC, you automatically trigger the change management workflow, which ensures that critical operations like backing out, testing, and stakeholder communication are planned in a controlled, compliant manner.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Windows Update Failures
Key term
Operating system
An operating system (OS) is the core software that manages a computer's hardware and software resources, providing common services for computer programs.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.