220-1102 Operational Procedures Practice Question
A technician has just applied a critical security patch to a file server during an approved maintenance window. The patch was installed successfully and the server is functioning correctly. According to change management best practices, what should the technician do NEXT?
⚠ Common exam trap
Watch out — candidates often assume a reboot is always necessary after patching (Option B) or that user notification is the immediate priority (Option A), but CompTIA emphasizes that documentation and change record closure are the mandatory next steps in the change management process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the change record with the implementation results
Change management best practices require that after any change is implemented, the technician must update the change record with the implementation results, including success confirmation, any deviations, and post-implementation verification. This ensures auditability, rollback documentation, and closure of the change request per ITIL framework guidelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately inform all users that the server is secure and patched
Why it's wrong here
While notifying users that a server is secure and patched is a courtesy, the change management process mandates that the technician first document the implementation results in the change record. Only after the outcome is formally recorded and verified should the communication plan be executed. Premature alerts can spread incomplete information if post-patch monitoring reveals issues, undermining trust and complicating the audit trail.
- ✗
Restart the server to ensure the patch is fully applied
Why it's wrong here
Restarting the server without consulting the vendor's patch documentation risks unnecessary downtime and can disrupt active user sessions. Many file-server security patches are designed to apply in-place without a reboot, and a restart is only warranted when the patch notes explicitly require it. An unplanned reboot also violates the change window and forces additional post-boot validation, making it an imprudent step before the change record is updated.
- ✓
Update the change record with the implementation results
Why this is correct
Updating the change record with the implementation results is the definitive action that closes the change management loop. It creates an authoritative audit trail, documents the actual outcome versus the plan, and provides critical context for future troubleshooting, rollback decisions, and continuous improvement. Without this record, the organization loses visibility into what was changed and why, leaving the change unaccountable and unverifiable.
- ✗
Perform a full backup of the server to verify data integrity
Why it's wrong here
Performing a full backup immediately after a patch does not confirm the patch's effectiveness; it merely snapshots the current state, which may already be compromised if the patch failed. Backup integrity verification is a routine preventive measure that should occur before a change, not after, to allow a known-good recovery point. Moreover, a full backup consumes significant I/O and storage, and the change management workflow prioritizes documentation over such secondary operational tasks.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.