
Certified Information Systems Security Professional
Domain 7Objective 9
7.9 - Understand and Participate in Change Management Processes CISSP Practice Questions (Page 5)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
13%of the exam
Questions 21–25
- 21
A database administrator is planning to apply a critical security patch to the organization's customer database. The patch will require a brief downtime of the database service. According to change management best practices, what should the administrator do before implementing the change?
Select an answer first - 22
What is the correct sequence of steps in a typical change management process?
Select an answer first - 23
A company has a Change Advisory Board (CAB) composed of IT managers, security officers, and business unit representatives. A request to upgrade the email server to a new version has been submitted. The change is considered a standard change because it is a routine upgrade that has been performed multiple times. What is the most appropriate way to handle this change?
Select an answer first - 24
A company is implementing a new email filtering system that will affect all employees. The change has been approved and is scheduled for implementation. What is the most important communication step to take before the implementation?
Select an answer first - 25
Which of the following should be considered during a security impact assessment of a proposed change?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.