Topic 03 Practice Test 1 covers Change Management and Security for CompTIA Security+ SY0-701 and maps to objective 1.3: Explain the importance of change management processes and the impact to security. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
The control set for a controlled production-change review must address both evaluation of how a proposed change may affect systems, users, security controls, and business processes and documented, repeatable set of steps for performing routine operational tasks consistently. Which TWO choices map directly to those needs? Choose TWO.
- Configuration documentation
- Standard operating procedure
- Impact analysis
- Maintenance window
- Backout plan
Correct Answers: B, C
Correct Answers
Answer B is correct because Standard operating procedure means a documented, repeatable set of steps for performing routine operational tasks consistently. One required function is exactly what this option provides. Backout plan may be useful elsewhere, but it is used for a documented method for reversing a change if implementation causes unacceptable problems.
Answer C is correct because Impact analysis means evaluation of how a proposed change may affect systems, users, security controls, and business processes. This selection maps directly to one of the named needs. Configuration documentation addresses updating diagrams, procedures, and configuration records so they match the post-change environment, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Configuration documentation means updating diagrams, procedures, and configuration records so they match the post-change environment. Every answer slot must map to a stated requirement. The correct set is Impact analysis, Standard operating procedure, so this option cannot replace one of those selections.
Answer D is incorrect because Maintenance window means a scheduled period during which disruptive changes can be implemented with controlled operational impact. The required choices are Impact analysis, Standard operating procedure. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. The question requires exactly 2 selections: Impact analysis, Standard operating procedure. This option falls outside that required set. For example, Impact analysis is required for evaluation of how a proposed change may affect systems, users, security controls, and business processes.
Question 2
To preserve change history and support controlled recovery, which security approach should be selected?
- Maintenance window
- Stakeholder review
- Version control
- Allow list and deny list review
Correct Answer: C
Correct Answer
Answer C is correct because Version control means tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back. The requirement maps directly to this function, whereas Maintenance window is aimed at a scheduled period during which disruptive changes can be implemented with controlled operational impact.
Incorrect Answers
Answer A is incorrect because Maintenance window refers to a scheduled period during which disruptive changes can be implemented with controlled operational impact. The question is not asking for this function. It is testing tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back, so Version control is the stronger fit.
Answer B is incorrect because Stakeholder review refers to involvement of affected business and technical parties before a change is made. The key mismatch is functional: Version control addresses tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back, the need stated by the question.
Answer D is incorrect because Allow list and deny list review refers to validation that access-control entries still permit only intended items and block known-unwanted items after a change. The concept is valid, but it does not match this stem. The required function is tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back, which maps to Version control.
Question 3
What is a scheduled period during which disruptive changes can be implemented with controlled operational impact?
- Stakeholder review
- Maintenance window
- Test results
- Impact analysis
Correct Answer: B
Correct Answer
Answer B is correct because Maintenance window means a scheduled period during which disruptive changes can be implemented with controlled operational impact. The deciding point is functional fit: this option covers the stated need, while Impact analysis addresses evaluation of how a proposed change may affect systems, users, security controls, and business processes.
Incorrect Answers
Answer A is incorrect because Stakeholder review refers to involvement of affected business and technical parties before a change is made. The key mismatch is functional: Maintenance window addresses a scheduled period during which disruptive changes can be implemented with controlled operational impact, the need stated by the question.
Answer C is incorrect because Test results refers to evidence from validation activities that demonstrates whether the proposed change behaves as expected. The key mismatch is functional: Maintenance window addresses a scheduled period during which disruptive changes can be implemented with controlled operational impact, the need stated by the question.
Answer D is incorrect because Impact analysis refers to evaluation of how a proposed change may affect systems, users, security controls, and business processes. The concept is valid, but it does not match this stem. The required function is a scheduled period during which disruptive changes can be implemented with controlled operational impact, which maps to Maintenance window.
Question 4
To perform restarts or outages at an approved low-risk time, which security approach should be selected?
- Maintenance window
- Standard operating procedure
- Backout plan
- Test results
Correct Answer: A
Correct Answer
Answer A is correct because Maintenance window means a scheduled period during which disruptive changes can be implemented with controlled operational impact. That is the function the question is testing. Backout plan would instead be used for a documented method for reversing a change if implementation causes unacceptable problems.
Incorrect Answers
Answer B is incorrect because Standard operating procedure refers to a documented, repeatable set of steps for performing routine operational tasks consistently. The question is not asking for this function. It is testing a scheduled period during which disruptive changes can be implemented with controlled operational impact, so Maintenance window is the stronger fit.
Answer C is incorrect because Backout plan refers to a documented method for reversing a change if implementation causes unacceptable problems. The concept is valid, but it does not match this stem. The required function is a scheduled period during which disruptive changes can be implemented with controlled operational impact, which maps to Maintenance window.
Answer D is incorrect because Test results refers to evidence from validation activities that demonstrates whether the proposed change behaves as expected. The concept is valid, but it does not match this stem. The required function is a scheduled period during which disruptive changes can be implemented with controlled operational impact, which maps to Maintenance window.
Question 5
Which term describes validation that access-control entries still permit only intended items and block known-unwanted items after a change?
- Test results
- Change ownership
- Approval process
- Allow list and deny list review
Correct Answer: D
Correct Answer
Answer D is correct because Allow list and deny list review means validation that access-control entries still permit only intended items and block known-unwanted items after a change. That makes it the best answer here; Change ownership addresses clear assignment of responsibility for planning, implementing, and following up on a change, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Test results refers to evidence from validation activities that demonstrates whether the proposed change behaves as expected. The key mismatch is functional: Allow list and deny list review addresses validation that access-control entries still permit only intended items and block known-unwanted items after a change, the need stated by the question.
Answer B is incorrect because Change ownership refers to clear assignment of responsibility for planning, implementing, and following up on a change. The scenario instead requires validation that access-control entries still permit only intended items and block known-unwanted items after a change, which is why Allow list and deny list review is the better answer; this option serves the different function defined above.
Answer C is incorrect because Approval process refers to the formal authorization step that ensures a proposed change is reviewed before implementation. The concept is valid, but it does not match this stem. The required function is validation that access-control entries still permit only intended items and block known-unwanted items after a change, which maps to Allow list and deny list review.
Question 6
To restore the prior known-good state when a deployment fails, which security approach should be selected?
- Change ownership
- Stakeholder review
- Standard operating procedure
- Backout plan
Correct Answer: D
Correct Answer
Answer D is correct because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. That makes it the best answer here; Stakeholder review addresses involvement of affected business and technical parties before a change is made, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Change ownership refers to clear assignment of responsibility for planning, implementing, and following up on a change. The question is not asking for this function. It is testing a documented method for reversing a change if implementation causes unacceptable problems, so Backout plan is the stronger fit.
Answer B is incorrect because Stakeholder review refers to involvement of affected business and technical parties before a change is made. That concept can be valid in another scenario, but this question is testing a documented method for reversing a change if implementation causes unacceptable problems; Backout plan therefore fits the requirement more directly.
Answer C is incorrect because Standard operating procedure refers to a documented, repeatable set of steps for performing routine operational tasks consistently. This could be appropriate elsewhere, but the required function is a documented method for reversing a change if implementation causes unacceptable problems; that makes Backout plan the precise choice.
Question 7
Which term describes updating diagrams, procedures, and configuration records so they match the post-change environment?
- Configuration documentation
- Backout plan
- Allow list and deny list review
- Maintenance window
Correct Answer: A
Correct Answer
Answer A is correct because Configuration documentation means updating diagrams, procedures, and configuration records so they match the post-change environment. This is the precise fit for the scenario. Allow list and deny list review serves the different purpose of validation that access-control entries still permit only intended items and block known-unwanted items after a change.
Incorrect Answers
Answer B is incorrect because Backout plan refers to a documented method for reversing a change if implementation causes unacceptable problems. The key mismatch is functional: Configuration documentation addresses updating diagrams, procedures, and configuration records so they match the post-change environment, the need stated by the question.
Answer C is incorrect because Allow list and deny list review refers to validation that access-control entries still permit only intended items and block known-unwanted items after a change. The key mismatch is functional: Configuration documentation addresses updating diagrams, procedures, and configuration records so they match the post-change environment, the need stated by the question.
Answer D is incorrect because Maintenance window refers to a scheduled period during which disruptive changes can be implemented with controlled operational impact. This could be appropriate elsewhere, but the required function is updating diagrams, procedures, and configuration records so they match the post-change environment; that makes Configuration documentation the precise choice.
Question 8
To avoid breaking upstream or downstream services during implementation, which security approach should be selected?
- Maintenance window
- Dependency analysis
- Test results
- Standard operating procedure
Correct Answer: B
Correct Answer
Answer B is correct because Dependency analysis means identification of systems, applications, services, or integrations that rely on the component being changed. That is the function the question is testing. Standard operating procedure would instead be used for a documented, repeatable set of steps for performing routine operational tasks consistently.
Incorrect Answers
Answer A is incorrect because Maintenance window refers to a scheduled period during which disruptive changes can be implemented with controlled operational impact. This could be appropriate elsewhere, but the required function is identification of systems, applications, services, or integrations that rely on the component being changed; that makes Dependency analysis the precise choice.
Answer C is incorrect because Test results refers to evidence from validation activities that demonstrates whether the proposed change behaves as expected. The key mismatch is functional: Dependency analysis addresses identification of systems, applications, services, or integrations that rely on the component being changed, the need stated by the question.
Answer D is incorrect because Standard operating procedure refers to a documented, repeatable set of steps for performing routine operational tasks consistently. The concept is valid, but it does not match this stem. The required function is identification of systems, applications, services, or integrations that rely on the component being changed, which maps to Dependency analysis.
Question 9
Reviewers working through a controlled production-change review identify three separate needs: clear assignment of responsibility for planning, implementing, and following up on a change; involvement of affected business and technical parties before a change is made; updating diagrams, procedures, and configuration records so they match the post-change environment. Which THREE choices map to those needs? Choose THREE.
- Test results
- Impact analysis
- Backout plan
- Change ownership
- Configuration documentation
- Stakeholder review
Correct Answers: D, E, F
Correct Answers
Answer D is correct because Change ownership means clear assignment of responsibility for planning, implementing, and following up on a change. One required function is exactly what this option provides. Backout plan may be useful elsewhere, but it is used for a documented method for reversing a change if implementation causes unacceptable problems.
Answer E is correct because Configuration documentation means updating diagrams, procedures, and configuration records so they match the post-change environment. This option satisfies a specific requirement in the stem; Backout plan serves a documented method for reversing a change if implementation causes unacceptable problems and therefore is not interchangeable with it.
Answer F is correct because Stakeholder review means involvement of affected business and technical parties before a change is made. The fixed-count item needs this function in the answer set. Backout plan covers a documented method for reversing a change if implementation causes unacceptable problems, a different requirement.
Incorrect Answers
Answer A is incorrect because Test results means evidence from validation activities that demonstrates whether the proposed change behaves as expected. The required choices are Stakeholder review, Change ownership, Configuration documentation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Impact analysis means evaluation of how a proposed change may affect systems, users, security controls, and business processes. The fixed-count answer set is Stakeholder review, Change ownership, Configuration documentation; this option does not fill one of those named functions.
Answer C is incorrect because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. The required choices are Stakeholder review, Change ownership, Configuration documentation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 10
To understand likely consequences before approving implementation, which security approach should be selected?
- Maintenance window
- Impact analysis
- Allow list and deny list review
- Backout plan
Correct Answer: B
Correct Answer
Answer B is correct because Impact analysis means evaluation of how a proposed change may affect systems, users, security controls, and business processes. That makes it the best answer here; Maintenance window addresses a scheduled period during which disruptive changes can be implemented with controlled operational impact, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Maintenance window refers to a scheduled period during which disruptive changes can be implemented with controlled operational impact. The scenario instead requires evaluation of how a proposed change may affect systems, users, security controls, and business processes, which is why Impact analysis is the better answer; this option serves the different function defined above.
Answer C is incorrect because Allow list and deny list review refers to validation that access-control entries still permit only intended items and block known-unwanted items after a change. The question is not asking for this function. It is testing evaluation of how a proposed change may affect systems, users, security controls, and business processes, so Impact analysis is the stronger fit.
Answer D is incorrect because Backout plan refers to a documented method for reversing a change if implementation causes unacceptable problems. The concept is valid, but it does not match this stem. The required function is evaluation of how a proposed change may affect systems, users, security controls, and business processes, which maps to Impact analysis.
Question 11
What is a documented method for reversing a change if implementation causes unacceptable problems?
- Stakeholder review
- Approval process
- Backout plan
- Version control
Correct Answer: C
Correct Answer
Answer C is correct because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. That is the function the question is testing. Stakeholder review would instead be used for involvement of affected business and technical parties before a change is made.
Incorrect Answers
Answer A is incorrect because Stakeholder review refers to involvement of affected business and technical parties before a change is made. The key mismatch is functional: Backout plan addresses a documented method for reversing a change if implementation causes unacceptable problems, the need stated by the question.
Answer B is incorrect because Approval process refers to the formal authorization step that ensures a proposed change is reviewed before implementation. That concept can be valid in another scenario, but this question is testing a documented method for reversing a change if implementation causes unacceptable problems; Backout plan therefore fits the requirement more directly.
Answer D is incorrect because Version control refers to tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back. This could be appropriate elsewhere, but the required function is a documented method for reversing a change if implementation causes unacceptable problems; that makes Backout plan the precise choice.
Question 12
Two requirements remain open in a controlled production-change review: formal authorization step that ensures a proposed change is reviewed before implementation; clear assignment of responsibility for planning, implementing, and following up on a change. Which TWO options close those specific gaps? Choose TWO.
- Test results
- Approval process
- Configuration documentation
- Change ownership
- Maintenance window
Correct Answers: B, D
Correct Answers
Answer B is correct because Approval process means the formal authorization step that ensures a proposed change is reviewed before implementation. One required function is exactly what this option provides. Maintenance window may be useful elsewhere, but it is used for a scheduled period during which disruptive changes can be implemented with controlled operational impact.
Answer D is correct because Change ownership means clear assignment of responsibility for planning, implementing, and following up on a change. This option satisfies a specific requirement in the stem; Configuration documentation serves updating diagrams, procedures, and configuration records so they match the post-change environment and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Test results means evidence from validation activities that demonstrates whether the proposed change behaves as expected. Every answer slot must map to a stated requirement. The correct set is Approval process, Change ownership, so this option cannot replace one of those selections.
Answer C is incorrect because Configuration documentation means updating diagrams, procedures, and configuration records so they match the post-change environment. The scenario calls for Approval process, Change ownership. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Maintenance window means a scheduled period during which disruptive changes can be implemented with controlled operational impact. The scenario calls for Approval process, Change ownership. Selecting this option would leave one of those required functions uncovered.
Question 13
What is a documented, repeatable set of steps for performing routine operational tasks consistently?
- Configuration documentation
- Dependency analysis
- Standard operating procedure
- Maintenance window
Correct Answer: C
Correct Answer
Answer C is correct because Standard operating procedure means a documented, repeatable set of steps for performing routine operational tasks consistently. This is the precise fit for the scenario. Dependency analysis serves the different purpose of identification of systems, applications, services, or integrations that rely on the component being changed.
Incorrect Answers
Answer A is incorrect because Configuration documentation refers to updating diagrams, procedures, and configuration records so they match the post-change environment. The concept is valid, but it does not match this stem. The required function is a documented, repeatable set of steps for performing routine operational tasks consistently, which maps to Standard operating procedure.
Answer B is incorrect because Dependency analysis refers to identification of systems, applications, services, or integrations that rely on the component being changed. This could be appropriate elsewhere, but the required function is a documented, repeatable set of steps for performing routine operational tasks consistently; that makes Standard operating procedure the precise choice.
Answer D is incorrect because Maintenance window refers to a scheduled period during which disruptive changes can be implemented with controlled operational impact. The scenario instead requires a documented, repeatable set of steps for performing routine operational tasks consistently, which is why Standard operating procedure is the better answer; this option serves the different function defined above.
Question 14
The control set for a controlled production-change review must address both documented method for reversing a change if implementation causes unacceptable problems and identification of systems, applications, services, or integrations that rely on the component being changed. Which TWO choices map directly to those needs? Choose TWO.
- Configuration documentation
- Standard operating procedure
- Backout plan
- Dependency analysis
- Stakeholder review
Correct Answers: C, D
Correct Answers
Answer C is correct because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. It belongs in the fixed-count answer set because it covers one of the stated requirements. Standard operating procedure instead serves a documented, repeatable set of steps for performing routine operational tasks consistently and cannot replace this function.
Answer D is correct because Dependency analysis means identification of systems, applications, services, or integrations that rely on the component being changed. The fixed-count item needs this function in the answer set. Stakeholder review covers involvement of affected business and technical parties before a change is made, a different requirement.
Incorrect Answers
Answer A is incorrect because Configuration documentation means updating diagrams, procedures, and configuration records so they match the post-change environment. The required choices are Backout plan, Dependency analysis. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Standard operating procedure means a documented, repeatable set of steps for performing routine operational tasks consistently. The fixed-count answer set is Backout plan, Dependency analysis; this option does not fill one of those named functions.
Answer E is incorrect because Stakeholder review means involvement of affected business and technical parties before a change is made. The scenario calls for Backout plan, Dependency analysis. Selecting this option would leave one of those required functions uncovered.
Question 15
To make one accountable party responsible for the change lifecycle, which security approach should be selected?
- Version control
- Dependency analysis
- Impact analysis
- Change ownership
Correct Answer: D
Correct Answer
Answer D is correct because Change ownership means clear assignment of responsibility for planning, implementing, and following up on a change. That is the function the question is testing. Impact analysis would instead be used for evaluation of how a proposed change may affect systems, users, security controls, and business processes.
Incorrect Answers
Answer A is incorrect because Version control refers to tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back. The scenario instead requires clear assignment of responsibility for planning, implementing, and following up on a change, which is why Change ownership is the better answer; this option serves the different function defined above.
Answer B is incorrect because Dependency analysis refers to identification of systems, applications, services, or integrations that rely on the component being changed. The concept is valid, but it does not match this stem. The required function is clear assignment of responsibility for planning, implementing, and following up on a change, which maps to Change ownership.
Answer C is incorrect because Impact analysis refers to evaluation of how a proposed change may affect systems, users, security controls, and business processes. The scenario instead requires clear assignment of responsibility for planning, implementing, and following up on a change, which is why Change ownership is the better answer; this option serves the different function defined above.
Question 16
An architect working on a controlled production-change review needs one capability that provides formal authorization step that ensures a proposed change is reviewed before implementation and another that provides documented method for reversing a change if implementation causes unacceptable problems. Which TWO selections are the best match? Choose TWO.
- Approval process
- Backout plan
- Stakeholder review
- Change ownership
- Allow list and deny list review
Correct Answers: A, B
Correct Answers
Answer A is correct because Approval process means the formal authorization step that ensures a proposed change is reviewed before implementation. The fixed-count item needs this function in the answer set. Change ownership covers clear assignment of responsibility for planning, implementing, and following up on a change, a different requirement.
Answer B is correct because Backout plan means a documented method for reversing a change if implementation causes unacceptable problems. It belongs in the fixed-count answer set because it covers one of the stated requirements. Stakeholder review instead serves involvement of affected business and technical parties before a change is made and cannot replace this function.
Incorrect Answers
Answer C is incorrect because Stakeholder review means involvement of affected business and technical parties before a change is made. The fixed-count answer set is Backout plan, Approval process; this option does not fill one of those named functions.
Answer D is incorrect because Change ownership means clear assignment of responsibility for planning, implementing, and following up on a change. The required choices are Backout plan, Approval process. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Allow list and deny list review means validation that access-control entries still permit only intended items and block known-unwanted items after a change. The scenario calls for Backout plan, Approval process. Selecting this option would leave one of those required functions uncovered.
Question 17
Which term describes involvement of affected business and technical parties before a change is made?
- Stakeholder review
- Configuration documentation
- Impact analysis
- Dependency analysis
Correct Answer: A
Correct Answer
Answer A is correct because Stakeholder review means involvement of affected business and technical parties before a change is made. The deciding point is functional fit: this option covers the stated need, while Impact analysis addresses evaluation of how a proposed change may affect systems, users, security controls, and business processes.
Incorrect Answers
Answer B is incorrect because Configuration documentation refers to updating diagrams, procedures, and configuration records so they match the post-change environment. The concept is valid, but it does not match this stem. The required function is involvement of affected business and technical parties before a change is made, which maps to Stakeholder review.
Answer C is incorrect because Impact analysis refers to evaluation of how a proposed change may affect systems, users, security controls, and business processes. The scenario instead requires involvement of affected business and technical parties before a change is made, which is why Stakeholder review is the better answer; this option serves the different function defined above.
Answer D is incorrect because Dependency analysis refers to identification of systems, applications, services, or integrations that rely on the component being changed. The key mismatch is functional: Stakeholder review addresses involvement of affected business and technical parties before a change is made, the need stated by the question.
Question 18
A review during a controlled production-change review identifies two gaps. One requires formal authorization step that ensures a proposed change is reviewed before implementation. The other requires identification of systems, applications, services, or integrations that rely on the component being changed. Which TWO options should be included in the remediation plan? Choose TWO.
- Approval process
- Maintenance window
- Dependency analysis
- Version control
- Standard operating procedure
Correct Answers: A, C
Correct Answers
Answer A is correct because Approval process means the formal authorization step that ensures a proposed change is reviewed before implementation. The fixed-count item needs this function in the answer set. Maintenance window covers a scheduled period during which disruptive changes can be implemented with controlled operational impact, a different requirement.
Answer C is correct because Dependency analysis means identification of systems, applications, services, or integrations that rely on the component being changed. The fixed-count item needs this function in the answer set. Version control covers tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back, a different requirement.
Incorrect Answers
Answer B is incorrect because Maintenance window means a scheduled period during which disruptive changes can be implemented with controlled operational impact. The scenario calls for Approval process, Dependency analysis. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Version control means tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back. Every answer slot must map to a stated requirement. The correct set is Approval process, Dependency analysis, so this option cannot replace one of those selections.
Answer E is incorrect because Standard operating procedure means a documented, repeatable set of steps for performing routine operational tasks consistently. Every answer slot must map to a stated requirement. The correct set is Approval process, Dependency analysis, so this option cannot replace one of those selections.
Question 19
Which formal authorization step ensures a proposed change is reviewed before implementation?
- Approval process
- Stakeholder review
- Backout plan
- Version control
Correct Answer: A
Correct Answer
Answer A is correct because Approval process means the formal authorization step that ensures a proposed change is reviewed before implementation. The deciding point is functional fit: this option covers the stated need, while Stakeholder review addresses involvement of affected business and technical parties before a change is made.
Incorrect Answers
Answer B is incorrect because Stakeholder review refers to involvement of affected business and technical parties before a change is made. This could be appropriate elsewhere, but the required function is the formal authorization step that ensures a proposed change is reviewed before implementation; that makes Approval process the precise choice.
Answer C is incorrect because Backout plan refers to a documented method for reversing a change if implementation causes unacceptable problems. The question is not asking for this function. It is testing the formal authorization step that ensures a proposed change is reviewed before implementation, so Approval process is the stronger fit.
Answer D is incorrect because Version control refers to tracking revisions to code, configuration, or documents so changes can be identified, compared, and rolled back. This could be appropriate elsewhere, but the required function is the formal authorization step that ensures a proposed change is reviewed before implementation; that makes Approval process the precise choice.
Question 20
To surface dependencies, operational concerns, and business impact early, which security approach should be selected?
- Dependency analysis
- Stakeholder review
- Configuration documentation
- Change ownership
Correct Answer: B
Correct Answer
Answer B is correct because Stakeholder review means involvement of affected business and technical parties before a change is made. This matches the requirement as written. Change ownership can be valid in another context, but it is used for clear assignment of responsibility for planning, implementing, and following up on a change.
Incorrect Answers
Answer A is incorrect because Dependency analysis refers to identification of systems, applications, services, or integrations that rely on the component being changed. The question is not asking for this function. It is testing involvement of affected business and technical parties before a change is made, so Stakeholder review is the stronger fit.
Answer C is incorrect because Configuration documentation refers to updating diagrams, procedures, and configuration records so they match the post-change environment. This could be appropriate elsewhere, but the required function is involvement of affected business and technical parties before a change is made; that makes Stakeholder review the precise choice.
Answer D is incorrect because Change ownership refers to clear assignment of responsibility for planning, implementing, and following up on a change. The concept is valid, but it does not match this stem. The required function is involvement of affected business and technical parties before a change is made, which maps to Stakeholder review.