First Step Before Patching a Production System?
A technician needs to apply a high-priority patch to a production system. Which of the following steps should be taken first?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you recognize that change management authorization precedes any production modification — the trap is assuming that a high-priority patch exempts you from the request-and-approval process.
Applying a high-priority patch to a production system must begin with a change control request, not with the patch itself. This page explains why SY0-701 treats formal change management authorization as the mandatory first step before remediation touches production.
The most tempting wrong answer is D, applying the patch immediately because the vulnerability is labeled high priority. Urgency does not remove the need for documented authorization, impact review, and a rollback plan before production is altered.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Change management exists so that every modification to an IT environment is identified, assessed, authorized, and recorded before it happens, which is exactly what a change control request accomplishes. A high-priority patch is still a change to a production system, so the request must come first and should capture the risk, the implementation window, testing evidence, and a back-out plan. As Abcd123321 explains, change control is "the process that management uses to identify, document and authorize changes," and it minimizes disruption, unauthorized alterations, and errors. CompTIA's doctrine under objective 1.3 rewards governance before action, so C is the only step that logically precedes touching the server. Emergency change procedures may compress the timeline, but they still require authorization and after-the-fact documentation.Why the Other Options Are Wrong
Air gapping the system (A) is an extreme architectural action that would itself be a major unauthorized change and would take the production service offline without approval. Moving the system to a different network segment (B) neither remediates the vulnerability nor satisfies governance, and one learner who leaned toward segmentation admitted that "you need a Change Control Request first." Applying the patch directly (D) bypasses approval, testing, and rollback planning, and a failed patch on production without a change record is precisely the outage scenario change management is designed to prevent. None of A, B, or D is a prerequisite step; they are either reactions or consequences that follow an approved change.Community Comment Notes
Abcd123321 framed change control as the mechanism management uses to "identify, document and authorize changes," which matches the exam's emphasis on authorization before execution. dbrowndiver added that the request ensures the patch is applied systematically and with proper oversight, "reducing the chance of errors or unforeseen issues." 3037402 and MaxiPrince gave the same short verdict, and ProudFather stressed that the change request must come before any production modification. One learner, 9149f41, argued for segmenting the system but conceded the change control request would still be mandatory first, which actually reinforces C rather than undermining it.Official Reference
Exam Strategy
When a stem pairs urgency words such as high-priority patch or critical vulnerability with a production system, scan for the governance step before the technical action. CompTIA consistently rewards the process control (change request) over immediate remediation in change-management scenarios.
Frequently Asked Questions
Why not just apply the high-priority patch immediately?
Unauthorized patching risks an unplanned production outage with no rollback plan and creates a change management and audit violation, even when the vulnerability is urgent.
Does a high-priority patch bypass change management approval?
No. Emergency change procedures may shorten the timeline or allow verbal authorization, but the change must still be documented, approved, and reviewed afterward.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →