220-1102 Operational Procedures Practice Question
A technician is informed that a critical vulnerability is being actively exploited against a production web server. The vendor has released an emergency security patch. The company's change management policy requires all changes to be approved by the Change Advisory Board (CAB), but the CAB is not scheduled to meet for two days. What should the technician do FIRST?
⚠ Common exam trap
The trap is adhering too rigidly to change management procedures; candidates may choose to wait for CAB approval, but in active exploitation scenarios, immediate action is warranted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the patch immediately and then document the change
When a critical vulnerability is being actively exploited, immediate action is required to mitigate the threat. Applying the emergency patch first and documenting afterward is the correct approach because it prioritizes security over strict change management procedures. This is a common exception in change management policies for emergency security patches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply the patch immediately and then document the change
Why this is correct
Apply the critical patch immediately, then document it as an emergency change. This aligns with change management frameworks that allow expedited approval for urgent security patches to prevent ongoing exploitation. After implementation, submit the change to the CAB for retroactive approval, ensuring traceability and compliance. This balances urgent security remediation with governance and auditability.
- ✗
Wait for the next CAB meeting to get approval
Why it's wrong here
Waiting for a regularly scheduled CAB meeting introduces unacceptable delay during an active vulnerability exploitation. Emergency change procedures exist specifically for this scenario; standard change management approval cycles are not designed for time-sensitive security incidents. The longer the delay, the higher the risk of data compromise or service outage, making this noncompliant with incident response expectations.
- ✗
Deny the patch application until approval is obtained
Why it's wrong here
In an emergency change situation, the change advisory board (CAB) process is typically bypassed because waiting for approval leaves systems vulnerable. Denying the patch without a compensating control or alternative mitigation leaves the vulnerability exploitable, violating incident response and security best practices. The change management policy usually permits emergency changes with post-implementation review, so denial is not aligned with standard procedures.
- ✗
Send an email to all stakeholders requesting approval via reply
Why it's wrong here
Soliciting approval via reply-all email lacks the formal documentation and audit trail required for change management. It creates confusion over who authorized the change and provides no guarantee of a timely decision, while also being vulnerable to email delays or being overlooked. Proper emergency changes use a distinct approval path (e.g., a designated emergency CAB or incident response leader) that is documented and quickly acted on.
Go deeper
Related to this question
Learn chapter
IT Policies: AUP, BYOD, Password Policy
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.