Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is informed that a critical vulnerability is being actively exploited against a production web server. The vendor has released an emergency security patch. The company's change management policy requires all changes to be approved by the Change Advisory Board (CAB), but the CAB is not scheduled to meet for two days. What should the technician do FIRST?

⚠ Common exam trap

The trap is adhering too rigidly to change management procedures; candidates may choose to wait for CAB approval, but in active exploitation scenarios, immediate action is warranted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the patch immediately and then document the change

When a critical vulnerability is being actively exploited, immediate action is required to mitigate the threat. Applying the emergency patch first and documenting afterward is the correct approach because it prioritizes security over strict change management procedures. This is a common exception in change management policies for emergency security patches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply the patch immediately and then document the change

    Why this is correct

    Apply the critical patch immediately, then document it as an emergency change. This aligns with change management frameworks that allow expedited approval for urgent security patches to prevent ongoing exploitation. After implementation, submit the change to the CAB for retroactive approval, ensuring traceability and compliance. This balances urgent security remediation with governance and auditability.

  • ✗

    Wait for the next CAB meeting to get approval

    Why it's wrong here

    Waiting for a regularly scheduled CAB meeting introduces unacceptable delay during an active vulnerability exploitation. Emergency change procedures exist specifically for this scenario; standard change management approval cycles are not designed for time-sensitive security incidents. The longer the delay, the higher the risk of data compromise or service outage, making this noncompliant with incident response expectations.

  • ✗

    Deny the patch application until approval is obtained

    Why it's wrong here

    In an emergency change situation, the change advisory board (CAB) process is typically bypassed because waiting for approval leaves systems vulnerable. Denying the patch without a compensating control or alternative mitigation leaves the vulnerability exploitable, violating incident response and security best practices. The change management policy usually permits emergency changes with post-implementation review, so denial is not aligned with standard procedures.

  • ✗

    Send an email to all stakeholders requesting approval via reply

    Why it's wrong here

    Soliciting approval via reply-all email lacks the formal documentation and audit trail required for change management. It creates confusion over who authorized the change and provides no guarantee of a timely decision, while also being vulnerable to email delays or being overlooked. Proper emergency changes use a distinct approval path (e.g., a designated emergency CAB or incident response leader) that is documented and quickly acted on.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.