220-1102 Operational Procedures Practice Question
A technician is preparing to deploy a critical security patch to all company servers. The patch has been tested in a lab environment and approved by the Change Advisory Board (CAB). According to change management best practices, what is the NEXT step the technician should take?
⚠ Common exam trap
Watch out — candidates often assume CAB approval means immediate deployment is acceptable, but change management requires scheduling the implementation during an approved maintenance window to control risk and ensure proper communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule the deployment during a maintenance window
Change management best practices require scheduling the deployment during a maintenance window to minimize disruption, even after CAB approval and lab testing. This ensures that the patch is applied during a controlled period when rollback is feasible and impact on operations is limited.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Schedule the deployment during a maintenance window
Why this is correct
Scheduling the deployment during a maintenance window is the correct next action because it confines the patch installation to a predefined low-activity period, minimizing user impact and allowing for focused monitoring. A maintenance window also provides a natural boundary for change rollout and rollback, aligning with the organization's change management policy. This deliberate timing ensures that if the patch introduces issues, the team can respond within controlled downtime rather than during peak operations.
- ✗
Immediately deploy the patch to all servers
Why it's wrong here
Deploying the patch immediately to all servers bypasses the change management process, which likely requires approval from the CAB or at least a scheduled change record. Without a designated maintenance window, the deployment could occur during peak business hours, causing unexpected service disruption and user-facing downtime. Moreover, an immediate parallel push to every server leaves no room for a staged rollout or phased verification, making it impossible to contain a faulty patch before it spreads across the environment.
- ✗
Submit a rollback plan to the CAB
Why it's wrong here
Submitting a rollback plan to the CAB after the change has already been approved demonstrates a failure to include essential risk mitigation in the original change request. A proper change request must contain the rollback strategy from the outset, as the CAB evaluates the change based on that plan before granting approval. By the time you are preparing to deploy, submitting a separate rollback plan is procedurally incorrect and would delay the change while the CAB re-reviews, rather than ensuring the deployment goes forward safely.
- ✗
Notify all users of the patch deployment
Why it's wrong here
Notifying all users of the patch deployment is part of the communication plan, but it is not the primary action needed at this stage because scheduling the maintenance window must come first. You cannot accurately inform users about the timing or expected downtime until the deployment window is defined and approved. Additionally, a mass user notification may be inappropriate for an internal security patch that requires no user action, making it a secondary step after the change is scheduled and documented.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.