Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is performing a scheduled maintenance task to apply security patches to a server. The change was approved as a standard change with a predefined backout plan. During the patching, the server fails to reboot and becomes unresponsive. According to change management best practices, what should the technician do FIRST?

⚠ Common exam trap

Candidates often think immediate escalation to the CAB is required for any failed change, but standard changes with a predefined backout plan prioritize execution of that plan first to restore service quickly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement the backout plan

The change was approved as a standard change with a predefined backout plan. When a server fails to reboot after patching, the first action per change management best practices is to execute the backout plan to restore the server to its previous known-good state, minimizing downtime and risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately escalate to the Change Advisory Board

    Why it's wrong here

    Escalating to the CAB as the very first response would leave the production service down while waiting for a group to convene, which is both slow and contrary to the approved change plan. Approved maintenance plans specify a backout sequence to be executed when an update causes unexpected behavior; the CAB is only notified or consulted after restorative steps have failed or if the failure requires an emergency change. Thus, escalation is a governance follow-up, not a troubleshooting action.

  • ✓

    Implement the backout plan

    Why this is correct

    The backout plan is the predefined, tested set of reverse steps created during change planning, so executing it immediately returns the server to its last known-good state and restores service with minimal additional downtime. Rolling back the recent security patch or configuration change should be done before analyzing root cause in depth, because the service is already affected and speed of recovery is critical. Successful backout re-establishes baseline operations, after which you can log the issue and evaluate whether the change can be remediated and retried.

  • ✗

    Contact the server vendor for support

    Why it's wrong here

    Calling the vendor for support is a reasonable later step if the failed backout reveals an unresolved product defect, but it should never precede executing the backout plan. Vendor interactions often involve long hold times and diagnostic interviews, and they have no knowledge of your specific change or environment, so doing this first needlessly prolongs the outage. Only after the backout is attempted and fails does external support become the appropriate escalation path.

  • ✗

    Reimage the server from a backup

    Why it's wrong here

    Reimaging from a backup is a data-destructive, time-intensive recovery option that also risks reintroducing vulnerabilities or losing post-backup configuration changes, so it is considered a last resort. The backout plan is specifically designed to undo the exact delta introduced by the maintenance, which is far less invasive than rebuilding the machine image and restoring data. Use reimaging only if the server is otherwise unrecoverable and a backout is no longer feasible.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

6 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician is scheduled to apply security patches to a server during a maintenance window. The change was approved as a standard change. Midway through the patching, the technician discovers that one of the patches is causing a critical line-of-business application to fail. According to change management best practices, what should the technician do first?

easy
  • A.Continue applying all remaining patches as planned
  • ✓ B.Consult the change plan for rollback procedures
  • C.Immediately inform all users of the outage
  • D.Reboot the server and hope the application recovers

Why B: Change management best practices require that any deviation from the planned change—such as a patch causing a critical application failure—must be handled by first consulting the change plan for documented rollback procedures. This ensures a controlled, pre-approved method to revert the server to its previous stable state, minimizing downtime and risk. The technician should not improvise or escalate without following the approved plan.

Variation 2. A technician is applying a security patch to a file server as part of an approved change. During the patch installation, the server fails to reboot and the technician is unable to start the server. According to change management best practices, what should the technician do FIRST?

easy
  • A.Contact the vendor for support
  • B.Notify the CAB of the failure
  • ✓ C.Execute the backout plan
  • D.Continue trying to reboot the server

Why C: Change management best practices require that any change with a risk of failure must include a documented backout plan. When a patch installation causes a server to fail to reboot, the immediate priority is to restore service by executing the backout plan, which typically involves rolling back the patch or restoring from a known good backup. This minimizes downtime and follows the principle of first restoring operations before escalating or investigating further.

Variation 3. A company follows a strict change management process. A technician is applying a critical security patch to a web server during a scheduled maintenance window. The patch was fully tested in a lab environment and approved by the Change Advisory Board (CAB). During the installation, the technician discovers that the patch requires a software dependency that is not installed on the server. According to change management best practices, what should the technician do FIRST?

medium
  • A.Install the required dependency and then proceed with the patch
  • ✓ B.Abort the change and follow the backout plan to restore the server
  • C.Contact the CAB for immediate approval of the dependency
  • D.Apply the patch anyway and monitor the server for issues

Why B: Change management best practices require that any deviation from the approved change plan—such as an unplanned dependency—must be treated as a failed change. The technician should immediately abort the installation and execute the backout plan to restore the server to its pre-change state, then report the issue to the CAB for re-evaluation. Installing an untested dependency without prior approval violates the integrity of the change process and could introduce unforeseen instability or security risks.

Variation 4. A technician is applying a critical security patch to a production database server. The patch was fully tested in a lab environment and approved by the Change Advisory Board (CAB). During the scheduled maintenance window, the technician begins the installation. Halfway through, the server becomes unresponsive and fails to restart. Which of the following should the technician do FIRST according to change management best practices?

easy
  • A.Reboot the server and attempt the patch installation again.
  • ✓ B.Execute the prepared rollback plan to restore the server to its previous state.
  • C.Contact the software vendor for support before taking any other action.
  • D.Perform a full system restore from the most recent backup.

Why B: The correct first step is to execute the prepared rollback plan. Change management best practices require that any change, especially a critical security patch on a production server, must have a documented rollback procedure approved by the CAB alongside the change. Since the server became unresponsive and failed to restart during the patch installation, the technician must immediately revert to the known-good state using the pre-tested rollback plan to minimize downtime and data loss.

Variation 5. A technician is applying a critical security patch to a production database server during a scheduled maintenance window. The patch was tested in a lab environment and approved by the Change Advisory Board (CAB). The patch installs successfully, but after the server reboots, a core database service fails to start. A system state backup was taken before the change. According to change management best practices, what should the technician do FIRST?

hard
  • A.Contact the software vendor for support before making any changes.
  • ✓ B.Execute the backout plan by restoring the system state backup.
  • C.Reboot the server again to see if the service starts on a second attempt.
  • D.Inform the CAB of the failure and wait for further instructions before taking action.

Why B: Change management best practices require executing the pre-approved backout plan immediately when a change fails, especially when a system state backup is available. Restoring the system state backup reverts the server to its pre-patch configuration, minimizing downtime and ensuring the database service can start again. Waiting or experimenting (rebooting, contacting vendors, or waiting for CAB) violates the principle of rapid recovery within the scheduled maintenance window.

Variation 6. A technician is applying a critical security patch to a web server during a scheduled maintenance window. The patch was tested in a lab and approved by the Change Advisory Board. During the installation, the server becomes unresponsive and will not boot. The technician has a backup of the server configuration and a system state backup. According to change management best practices, what should the technician do FIRST?

medium
  • A.Reinstall the operating system
  • ✓ B.Restore the server from the system state backup
  • C.Contact the software vendor for support
  • D.Document the failure and continue with the patch

Why B: The system state backup contains the operating system, registry, and critical boot files, making it the fastest way to restore the server to a bootable state after a failed patch installation. Change management best practices prioritize rolling back to the last known good configuration before escalating to more destructive or time-consuming options.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.