220-1102 Operational Procedures Practice Question
A technician has received approval from the Change Advisory Board (CAB) to update the firmware on a critical database server. The change window is scheduled for 1:00 AM. At 12:45 AM, the technician begins the update, but mid-process the server loses power due to an electrical fault. Upon power restoration, the server fails to boot. The technician has a verified full backup. According to change management and incident response procedures, what should the technician do FIRST?
⚠ Common exam trap
Many candidates assume a verified backup means immediate restoration is the safest action, but change management and incident response protocols require notification and authorization first to maintain process integrity and avoid compounding the issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inform the change manager of the situation
According to change management and incident response procedures, the technician must first inform the change manager of the situation because the change window has not yet officially started (12:45 AM vs. 1:00 AM), and the server failure constitutes an unplanned incident. The change manager can then decide whether to authorize a rollback, extend the window, or escalate, ensuring proper documentation and accountability. Restoring from backup without notification violates the change management process and could lead to further issues if the root cause (e.g., electrical fault) is not addressed first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the server from the verified backup immediately
Why it's wrong here
Restoring from the verified backup is a technically plausible rollback, but the approved change plan does not authorize you to invoke that rollback unilaterally. In IT service management, any deviation from the agreed implementation or contingency steps must be cleared by the change manager, who will update the change record and confirm that the restore is warranted. Bypassing that notification could also overwrite critical diagnostic data and may expose other services to uncoordinated downtime.
- ✓
Inform the change manager of the situation
Why this is correct
The correct first action is to immediately report the failure to the change manager, because they retain authority over the change record and its formal rollback plans. The change manager, possibly with CAB input, determines whether to restore, repair, or escalate, ensuring every recovery step is documented and traceable. This preserves the audit trail required by change management procedures and prevents unauthorized or ad-hoc actions that could complicate the post-change review.
- ✗
Call the server vendor's technical support
Why it's wrong here
Vendor technical support is a troubleshooting resource, but invoking it without internal notification violates change management governance. Vendor personnel are not bound by your change plan, and their advice or actions might constitute an unapproved change to the environment, invalidating the change record. You must first inform the change manager, who can decide whether to escalate to the vendor as part of the contingency plan, thereby keeping the change process auditable and authorized.
- ✗
Attempt to repair the boot loader using recovery media
Why it's wrong here
Attempting a boot-loader repair with recovery media is an independent troubleshooting action that falls outside the approved change plan and its rollback procedure. Even if the repair seems obvious, the failure has already occurred within a change window, so all corrective steps must be sanctioned by the change manager to maintain control and documentation. Making unapproved repairs could create additional issues or mask the root cause, and it violates the expectation that technicians follow the change management process rather than improvise.
Go deeper
Related to this question
Learn chapter
Windows Device Manager
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.