220-1102 Question 679
Single answerEmergency changeA company’s line-of-business application becomes unreachable immediately after a security team identifies active exploitation of a newly disclosed vulnerability on the application server. The normal change approval meeting is scheduled for tomorrow, but the server must be patched and restarted within the next hour to reduce business risk. The help desk technician is asked to assist with the process. According to change-management best practices, what should happen FIRST?
- A
Implement the patch immediately without notifying anyone, because security incidents automatically bypass change management
- B
Submit and document an emergency change request, including risk, impact, and rollback information, then obtain expedited approval
- C
Wait for the standard change advisory board meeting so the change can follow the normal approval process
- D
Reimage the server instead of patching it, because emergency changes require the fastest technical fix rather than approval
Show answer and explanation
Correct answer: B
Explanation
Emergency change procedures are part of formal change management and are used when an urgent business or security need requires immediate action outside the normal approval timeline. In an A+ Core 2 context, the technician should recognize that urgent changes still need to be tracked and approved through an expedited process. Good practice includes documenting the reason for the emergency, affected assets, implementation plan, expected impact, communication plan, and rollback steps. After implementation, the change is typically reviewed and recorded for audit and lessons learned. This aligns with common IT service management best practices, such as those described in ITIL-style change enablement processes, where emergency changes are accelerated but not unmanaged.
- A. Incorrect.
This is incorrect. Even during a security incident, organizations should still follow the emergency change process rather than skipping change management entirely. Emergency changes are designed for urgent situations, but they still require documentation, communication, and authorization by the appropriate emergency approver or process owner. A common misconception is that urgency eliminates the need for control; in practice, urgency changes the approval path, not the need for governance.
- B. Correct.
This is correct. An emergency change is used when a critical issue requires rapid action outside the normal change window or approval cycle. Best practice is to document the reason for the change, affected systems, business impact, implementation steps, risk, and rollback plan, then get expedited approval through the organization's emergency change process. This allows the organization to respond quickly while maintaining accountability and reducing the chance of additional outages.
- C. Incorrect.
This is incorrect. Waiting for the normal approval meeting would delay mitigation of an actively exploited vulnerability and unnecessarily increase organizational risk. Standard changes and normal changes follow routine scheduling, but emergency changes exist specifically for situations where the business cannot wait for the regular process.
- D. Incorrect.
This is incorrect. Reimaging the server may be more disruptive, may not address the immediate issue appropriately, and is not what defines an emergency change. The key concept is not choosing the most drastic technical action; it is following the emergency change workflow to implement the least risky effective fix as quickly as necessary. Someone might choose this option by assuming that 'emergency' means taking the most aggressive action available, which is not a change-management best practice.