Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 2Objective 4

2.4 Manage Security Aspects of Change Control ISSMP Practice Questions (Page 1)

Part of the Systems Lifecycle Management domain, which accounts for 15% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
5concepts
15%of the exam

Questions 1–5

  1. 1application · medium

    A network administrator proposes a change to the company's firewall rules to allow a new vendor application to communicate with an internal database. The security team is asked to assess the change. Which of the following is the MOST important security consideration during the security impact analysis?

    Select an answer first
  2. 2foundation · easy

    What is the primary purpose of defining security criteria for change requests in a change control process?

    Select an answer first
  3. 3expert · hard · select all that apply

    A company is implementing a new single sign-on (SSO) solution that will affect all employees and external partners. The change control process requires coordination with stakeholders. Which of the following stakeholders should be included in the change control process? (Select all that apply.)

    Select an answer first
  4. 4application · medium

    An organization has a change control process that requires all changes to be documented and tracked. A security administrator notices that a recent change to a firewall rule was implemented but the change request form was never completed. What is the MOST appropriate action for the security administrator to take?

    Select an answer first
  5. 5application · medium

    A company has a policy that all changes to production systems must be approved by the change advisory board (CAB). A developer submits an urgent change to fix a critical security vulnerability. The CAB is not scheduled to meet for another week. What is the BEST way to handle this situation while maintaining policy compliance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.