CISA Governance and Management of IT Practice Question
An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess the impact and risk of the proposed change
The first step in any change management process is to assess the impact and risk of the proposed change. This assessment informs subsequent steps such as approval, notification, and implementation. Option A (CAB approval) should occur after the impact and risk assessment is completed. Option B (notifying users) is typically done after the change is approved and scheduled. Option D (immediate implementation) bypasses the necessary assessment and approval steps, which is not best practice even for urgent threats—a risk assessment should still be conducted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtain approval from the change advisory board
Why it's wrong here
Approval comes after risk assessment.
- ✗
Notify all users of the planned change
Why it's wrong here
Notification is part of the process but not the first step.
- ✓
Assess the impact and risk of the proposed change
Why this is correct
Risk assessment is required before approval.
- ✗
Implement the change immediately to address an urgent threat
Why it's wrong here
Urgent changes still require documented risk acceptance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.