220-1102 Operational Procedures Practice Question
A technician is implementing a change to a firewall rule on a production server. After implementing the change, the technician documents the change in the change management system. Which step did the technician likely skip according to change management best practices?
⚠ Common exam trap
Candidates often confuse the order of change management steps, assuming that documentation is the final step and therefore nothing was skipped, when in fact the critical pre-implementation testing step was omitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Testing the change in a staging environment
The technician implemented the change directly on a production server without first testing it in a staging environment. Change management best practices require that all changes, especially those affecting security controls like firewall rules, be validated in a non-production environment to prevent unintended disruptions or vulnerabilities. Skipping this step increases the risk of misconfiguration, service outage, or security exposure in the live environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtaining approval from the CAB
Why it's wrong here
CAB approval is a governance step that typically occurs during the planning/authorization phase of change management, not during implementation itself. The scenario focuses on the implementation step and provides no evidence that approval was bypassed; formal sign-off might already be in place without being mentioned. Since the question asks for the most likely omitted step at the point of implementation, a missing CAB authorization is speculative and less directly indicated than skipping validation of the change.
- ✓
Testing the change in a staging environment
Why this is correct
Best practice for firewall rule changes mandates validating the rule's behavior in a staging or lab environment that mirrors the production server's network and security policies. Without pre-implementation testing, the technician risks introducing connectivity loss, security holes, or rule-order conflicts that surface only after the change is live. The scenario implies the technician applied the rule directly to production without any test pass, making this the clear missing step.
- ✗
Creating a backout plan
Why it's wrong here
While a backout plan is essential for minimizing downtime during failed changes, it is commonly documented in the change request and does not require execution at the moment of implementation. The scenario does not indicate the absence of a rollback strategy; even with no testing, the technician could have prepared a fallback such as reverting the rule or reloading a saved configuration. Testing, by contrast, is the prerequisite validation step that prevents failure altogether, whereas a backout plan merely reacts to it—thus the omitted test is the more probable gap in this scenario.
- ✗
Notifying stakeholders
Why it's wrong here
Stakeholder notification belongs to the communication plan typically executed during the planning phase, often in parallel with CAB coordination, rather than as an immediate implementation task. The scenario does not specify that users or network operations teams were left unaware; the change might have been pre-announced. Even if stakeholders were not notified, that omission would not directly explain a technical misconfiguration, whereas failing to test the firewall rule in a staging environment is the classic cause of production incidents.
Go deeper
Related to this question
Learn chapter
System File Checker (sfc /scannow)
Key term
Exposure
Exposure is the measure of potential loss or harm to an organization's assets when a vulnerability is exploited by a threat, often expressed as the window of time or degree of access an attacker has.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.