Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician has received approval from the Change Advisory Board (CAB) to apply a critical security patch to a production file server. What is the MOST important step the technician should take before applying the patch?

⚠ Common exam trap

A common mix-up: candidates choose 'Test the patch on a non-production server first' (Option D) because it sounds like best practice, but the question explicitly states CAB approval has already been given, meaning the patch is considered ready for production; the exam wants you to recognize that the immediate, hands-on step before applying any change to a live system is to ensure a recoverable backup exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a full backup of the server's data.

Before applying any patch—especially a critical security patch to a production file server—the most important step is to perform a full backup of the server's data. This ensures that if the patch causes unexpected failures, data corruption, or incompatibility, the server can be restored to its pre-patch state with minimal data loss. Backups are a fundamental risk mitigation step in change management, as they provide a rollback path that no other option guarantees.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify all users that the server will be offline.

    Why it's wrong here

    Notifying users of an upcoming outage is an operational communication step addressed in the change management process, but it does nothing to protect the integrity of the server's data during the patch. The goal of a pre-patch action is to create a recoverable state, and user notification alone cannot undo a failed patch. While important, it is secondary to the technical safeguard of a backup.

  • ✓

    Perform a full backup of the server's data.

    Why this is correct

    Performing a full backup of the server's data is the critical step because it creates a reliable, restorable snapshot of the current environment before any patch-induced changes are applied. If the patch corrupts system files, breaks dependencies, or causes data loss, a full backup allows you to quickly return to the pre-patch state, satisfying the change advisory board's requirement for a backout plan. This is the only option that directly enables rollback, making it the most appropriate immediate action.

  • ✗

    Disable the antivirus software to prevent conflicts.

    Why it's wrong here

    Disabling antivirus is not recommended and could actually increase risk during patching, as the system becomes temporarily vulnerable to malware attacks while the patch is being applied. Unless a specific vendor advisory says to disable security software, it is better to keep it enabled or use vendor-supplied exceptions to avoid conflicts. The temporary disablement also weakens the server's defense-in-depth precisely when it is most exposed.

  • ✗

    Test the patch on a non-production server first.

    Why it's wrong here

    Testing the patch on a non-production server is a valuable pre-deployment validation step, but it is not the immediate technical step required before applying to a production server. The change advisory board typically confirms that testing has already occurred, and even a tested patch can behave differently in production due to unique data, configuration, or load conditions. The immediate safeguard is a backup, which provides a production-specific rollback mechanism.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.