220-1102 Operational Procedures Practice Question
A technician needs to schedule a maintenance window to apply a critical security patch to a server. The update requires a reboot and will cause a brief service outage. Which of the following is the BEST way to communicate this change to affected stakeholders?
⚠ Common exam trap
Watch out — candidates often choose Option D (notify IT manager only) because they assume off-hours work eliminates the need for broader communication, but CompTIA emphasizes that all affected stakeholders must be notified in advance through the formal change process, regardless of the time of day.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the formal change request process to schedule, approve, and notify stakeholders in advance
It follows the formal change management process (ITIL/ITSM framework) which requires documenting the change, obtaining approval from the Change Advisory Board (CAB), and notifying all affected stakeholders well in advance. This ensures that the critical security patch is applied with minimal disruption, proper rollback planning, and compliance with organizational policies, especially when a reboot and service outage are involved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send an email to all users immediately before the reboot
Why it's wrong here
An email blast sent immediately before the reboot provides no lead time for users to save unsaved work, complete in-flight transactions, or decouple batch jobs, and it lacks a formal change record. Without a request for change (RFC) approved through a change advisory board, there is no documented risk assessment, rollback plan, or defined maintenance window, so the reboot is uncoordinated with other IT operations and cannot be audited. For a critical security update, the patch itself may also require a rollback strategy if the system fails to restart, which an ad-hoc email does not address.
- ✓
Use the formal change request process to schedule, approve, and notify stakeholders in advance
Why this is correct
Submitting a formal change request creates a documented record that includes a risk assessment, implementation steps, rollback plan, and a defined maintenance window. It routes the update through the change advisory board (CAB) for approval, ensuring that the critical security patch is reviewed against business impact and scheduled to avoid conflicts with other changes. Stakeholders—including system users, help desk, and IT managers—receive advance notification through the change calendar, and the post-implementation review confirms the patch was applied successfully, providing an audit trail for compliance.
- ✗
Place a notice on the server console and proceed with the update
Why it's wrong here
Posting a notice on the server console is effective only for a person physically at the machine; remote users and applications consuming the server's services never see it. This method bypasses the change management approval process entirely, leaving no formal audit trail or rollback plan, which is a problem for regulated environments that require evidence of authorized changes. Proceeding with the update on the spot also risks unplanned downtime for dependent systems, as the change window is not coordinated with operational teams or documented for post-incident analysis.
- ✗
Notify the IT manager only and perform the update during off-hours
Why it's wrong here
Limiting notification to the IT manager leaves the help desk, system users, and other operational teams in the dark, so they cannot preemptively inform affected parties or prepare for support calls during the outage. Performing the update during off-hours is not inherently low-risk for organizations with 24/7 workloads, global users, or scheduled overnight batch jobs, and the manager's verbal approval does not substitute for a documented risk assessment and rollback plan required by formal change control. The off-hours timing further reduces the opportunity for immediate support if the patch causes a failed boot or service corruption.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Windows Update Failures
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.