Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A developer finds a production bug on Friday afternoon. The fix has already passed staging, but the business wants the release to be reversible if the hotfix causes trouble. Which change-management practice best satisfies both speed and control?

⚠ Common exam trap

Test-takers frequently assume 'speed' means 'no process at all' (Option A), but CompTIA tests the understanding that emergency change procedures are designed to balance speed with control, not eliminate it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use an emergency change with a documented rollback plan and approval

An emergency change with a documented rollback plan and approval provides the fastest path to production while maintaining control. This practice aligns with ITIL's emergency change advisory board (ECAB) process, which allows expedited approval for critical fixes while requiring a tested rollback procedure to ensure reversibility. The business's requirement for speed is met by bypassing the normal change window, and control is preserved through mandatory documentation and approval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Bypass change control so the patch reaches production immediately

    Why it's wrong here

    Bypassing change control eliminates the required review, approval, and rollback planning, which can lead to uncontrolled modifications that destabilize the environment or introduce security flaws. In many frameworks, such as ITIL or regulated industries, this violates audit and compliance requirements, potentially resulting in penalties. Furthermore, without documentation, troubleshooting future incidents becomes harder, and the change cannot be properly communicated to stakeholders.

  • Wait for the next normal change window next week

    Why it's wrong here

    Waiting for the next scheduled window incorrectly treats an emergency as routine, prolonging production impact, whether that is a security vulnerability, data corruption, or service outage. Standard change windows are optimized for low-risk, pre-approved maintenance, not for urgent remediation, and many organizations restrict unplanned work during these windows anyway. The incident's severity requires an expedited path, not deferral to the next convenient slot.

  • Use an emergency change with a documented rollback plan and approval

    Why this is correct

    An emergency change is the designed mechanism for urgent fixes, allowing expedited approval from an emergency advisory board while still enforcing testing evidence and a clearly defined rollback plan. This process balances the need for speed with risk mitigation, ensuring that if the patch fails, you can reliably restore service to the previous state. Without such a formal process, the organization loses traceability and accountability for the change.

  • Freeze all production changes until the next monthly review meeting

    Why it's wrong here

    Freezing all changes until the next monthly review is an excessive control measure that blocks even the needed patch, leaving the production bug unresolved and the business impact continuing. Change freezes are normally reserved for known high-risk periods like holiday blackouts or major events, not for incident response, and applying one here would delay the fix without reducing risk. Additionally, it prevents any potential workaround changes that might mitigate the issue, making the situation worse.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.