CISA Practice Question: Information Systems Operations and Business Resilience
An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?
⚠ Common exam trap
It's easy for candidates to confuse 'Planned change' (a scheduling concept) with a formal ITIL change type, leading them to select Option A, but ITIL only recognizes Standard, Emergency, and Normal changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Emergency change – requires immediate implementation to resolve a major incident.
ITIL defines an Emergency change as one that must be implemented as soon as possible—often to resolve a major incident or security vulnerability. This change type bypasses the normal CAB approval cycle and uses a dedicated Emergency CAB (ECAB) process to authorize and implement the fix rapidly while still maintaining control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Planned change – scheduled during maintenance windows with no approval needed.
Why it's wrong here
Planned changes are not a distinct type; they may be standard or normal changes.
- ✓
Emergency change – requires immediate implementation to resolve a major incident.
Why this is correct
Correct definition of emergency change.
- ✓
Standard change – pre-approved, low risk, follows a defined procedure.
Why this is correct
Correct definition of standard change.
- ✗
Major change – requires executive approval and a separate risk assessment.
Why it's wrong here
ITIL does not define 'major' as a separate change type; it is typically a category within normal changes.
- ✓
Normal change – requires approval from the Change Advisory Board (CAB).
Why this is correct
Correct definition of normal change.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.