
Certified Information Systems Security Professional
Domain 7Objective 9
7.9 - Understand and Participate in Change Management Processes CISSP Practice Questions (Page 4)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
13%of the exam
Questions 16–20
- 16
Which type of change is pre-authorized and considered low risk, such as applying a routine security patch?
Select an answer first - 17
How does change management interact with incident management during an emergency change?
Select an answer first - 18
A security incident occurred when an attacker exploited a vulnerability in a web application. The incident response team applied an emergency change to patch the vulnerability. After the incident is contained, what is the most important follow-up action related to change management?
Select an answer first - 19
A company is planning to replace its entire network infrastructure, including routers, switches, and firewalls. This change will affect all employees and external customers. According to change management principles, how should this change be classified?
Select an answer first - 20
What is the purpose of a post-incident review in the context of change management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.