Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

⚠ Common exam trap

It's easy for candidates to confuse 'Planned change' (a scheduling concept) with a formal ITIL change type, leading them to select Option A, but ITIL only recognizes Standard, Emergency, and Normal changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Emergency change – requires immediate implementation to resolve a major incident.

ITIL defines an Emergency change as one that must be implemented as soon as possible—often to resolve a major incident or security vulnerability. This change type bypasses the normal CAB approval cycle and uses a dedicated Emergency CAB (ECAB) process to authorize and implement the fix rapidly while still maintaining control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Planned change – scheduled during maintenance windows with no approval needed.

    Why it's wrong here

    Planned changes are not a distinct type; they may be standard or normal changes.

  • Emergency change – requires immediate implementation to resolve a major incident.

    Why this is correct

    Correct definition of emergency change.

  • Standard change – pre-approved, low risk, follows a defined procedure.

    Why this is correct

    Correct definition of standard change.

  • Major change – requires executive approval and a separate risk assessment.

    Why it's wrong here

    ITIL does not define 'major' as a separate change type; it is typically a category within normal changes.

  • Normal change – requires approval from the Change Advisory Board (CAB).

    Why this is correct

    Correct definition of normal change.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.