Courseiva
Governance and Management of ITeasyMultiple ChoiceObjective-mapped

CISA Governance and Management of IT Practice Question

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assess the impact and risk of the proposed change

The first step in any change management process is to assess the impact and risk of the proposed change. This assessment informs subsequent steps such as approval, notification, and implementation. Option A (CAB approval) should occur after the impact and risk assessment is completed. Option B (notifying users) is typically done after the change is approved and scheduled. Option D (immediate implementation) bypasses the necessary assessment and approval steps, which is not best practice even for urgent threats—a risk assessment should still be conducted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Obtain approval from the change advisory board

    Why it's wrong here

    Approval comes after risk assessment.

  • Notify all users of the planned change

    Why it's wrong here

    Notification is part of the process but not the first step.

  • Assess the impact and risk of the proposed change

    Why this is correct

    Risk assessment is required before approval.

  • Implement the change immediately to address an urgent threat

    Why it's wrong here

    Urgent changes still require documented risk acceptance.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.