
Certified Information Systems Security Professional
Domain 7Objective 9
7.9 - Understand and Participate in Change Management Processes CISSP Practice Questions (Page 3)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
13%of the exam
Questions 11–15
- 11
A security analyst discovers that a critical vulnerability is being actively exploited in the organization's internet-facing web server. The vendor has released a patch, but applying it requires a service restart, which will cause a brief outage. The organization's change management policy requires all changes to go through the Change Advisory Board (CAB). What is the most appropriate course of action?
Select an answer first - 12
A security operations center (SOC) detects a zero-day vulnerability being exploited in the organization's email gateway. The vendor has released an emergency patch, but the patch has not been fully tested. The change management policy requires all changes to be approved by the CAB. What is the most appropriate action for the SOC to take?
Select an answer first - 13
Why is it important to document rollback procedures in a change request?
Select an answer first - 14
A change request has been submitted to update the organization's backup software. The change manager has created a change request that includes the reason for the change, the implementation plan, and the rollback plan. What additional information is critical to include in the change request?
Select an answer first - 15
A company is planning to implement a new single sign-on (SSO) solution that will integrate with its existing Active Directory. The change manager has submitted a request to the Change Advisory Board (CAB). What is the most important security consideration the CAB should evaluate before approving the change?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.