nerdexam
(ISC)2

CISSP · Question #680

What does the change management process entail?

The correct answer is D. Identify vulnerabilities. Change management is a structured process for controlling modifications to IT systems, and a core component is identifying vulnerabilities that changes may introduce or that necessitate the change.

Submitted by cyberguy42· Mar 5, 2026Security Operations

Question

What does the change management process entail?

Options

  • AObtain information security management approval.
  • BMaintain the integrity of the application.
  • CObtain feedback before implementation.
  • DIdentify vulnerabilities.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    11% (3)
  • D
    82% (23)

Why each option

Change management is a structured process for controlling modifications to IT systems, and a core component is identifying vulnerabilities that changes may introduce or that necessitate the change.

AObtain information security management approval.

Obtaining information security management approval may be one procedural step in some organizations, but it is not the defining or comprehensive description of what change management entails as a process.

BMaintain the integrity of the application.

Maintaining the integrity of the application is a broader security objective and a desired outcome, not a specific activity that defines the change management process itself.

CObtain feedback before implementation.

Obtaining feedback before implementation may be part of a change advisory board (CAB) review, but it is not the primary or defining element that characterizes what change management entails.

DIdentify vulnerabilities.Correct

Change management entails identifying vulnerabilities as part of evaluating the risk and impact of proposed changes to systems or applications. By identifying vulnerabilities, organizations can determine whether a change is necessary to remediate a security weakness and assess what new risks the change itself might introduce, making it a foundational step in the process.

Concept tested: Change management process and vulnerability identification

Source: https://www.nist.gov/publications/guide-enterprise-patch-management-planning-preventive-maintenance-software

Topics

#change management#vulnerability management#risk assessment#security operations

Community Discussion

No community discussion yet for this question.

Full CISSP Practice