
EC-CouncilCertified Chief Information Security Officer
Domain 3Objective 4
Change Management, Version Control, and Disaster Recovery CCISO Practice Questions (Page 4)
Part of the Security Program Management and Operations domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
11concepts
Questions 16–20
- 16
A company is updating its incident response playbooks. The security team wants to ensure that any changes to the playbooks are traceable and that the DR site uses the same version. What should the team implement?
Select an answer first - 17
A large healthcare organization is implementing a formal change management process. The Chief Information Security Officer (CISO) wants to ensure that the Change Advisory Board (CAB) includes members who can assess the security, operational, and business impact of proposed changes. Which composition of the CAB would best meet this objective?
Select an answer first - 18
A configuration management team is using a version control system to manage infrastructure-as-code scripts. The team has been experiencing issues where multiple engineers are overwriting each other's changes, and it is difficult to determine who made a specific change and why. Which set of version control best practices would most directly address these issues?
Select an answer first - 19
A database administrator (DBA) needs to apply a patch to a production database. The change management process requires a change request, impact assessment, and rollback plan. The DBA has completed the technical steps but has not yet updated the rollback plan. What should the DBA do before submitting the change for approval?
Select an answer first - 20
A company has a mature change management process and a version control system for its infrastructure code. The company is updating its disaster recovery plan to include new recovery procedures. The CISO wants to ensure that the DR plan is always aligned with the current state of the infrastructure. Which approach best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.