
Information Systems Security Engineering Professional
Domain 5Objective 3
Participate in Change Management ISSEP Practice Questions (Page 1)
Part of the Secure Operations, Change Management and Disposal domain, which accounts for 14% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
14%of the exam
Questions 1–5
- 1
A system engineer proposes a change to the authentication service that will reduce the session timeout from 60 minutes to 15 minutes to improve security. During the change review, the security engineer notes that the change will affect a legacy application that does not support re-authentication prompts and will terminate user sessions without warning. What is the most appropriate action for the security engineer to take?
Select an answer first - 2
Why is it necessary to update risk assessment documentation after an approved change is implemented?
Select an answer first - 3
A change request proposes to upgrade the operating system on all web servers from an older version to a newer one. The change review board is concerned about the impact on a custom web application that has not been tested on the new OS. What is the most appropriate action for the change review board to take?
Select an answer first - 4
What is the primary purpose of verification and validation of a change after implementation?
Select an answer first - 5
What is the primary purpose of a change review board (CRB) in the change management process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.