Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

⚠ Common exam trap

It's easy for candidates to confuse 'Planned change' (a scheduling concept) with a formal ITIL change type, leading them to select Option A, but ITIL only recognizes Standard, Emergency, and Normal changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Emergency change – requires immediate implementation to resolve a major incident.

Option B is correct because ITIL defines an emergency change as one that must be implemented immediately, typically to resolve a major incident or restore a critical service, and it follows an expedited approval path (e.g., Emergency CAB). Option C is correct because a standard change is a pre-authorized, low-risk, routine change with a documented procedure, so it does not require individual CAB review each time. Option E is correct because a normal change is the standard ITIL category that must be assessed and approved by the Change Advisory Board (CAB) before implementation. Option A is incorrect because planned changes are not a distinct ITIL change type and, more importantly, scheduled changes still require appropriate authorization rather than 'no approval needed.' Option D is incorrect because 'major change' is not one of the three ITIL change types; major changes are handled as normal or emergency changes with escalated approval and risk assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Planned change – scheduled during maintenance windows with no approval needed.

    Why it's wrong here

    ITIL requires every change, including planned ones, to pass through authorisation; scheduling in a maintenance window does not remove the need for approval. A no-approval planned change would fit only pre-authorised standard changes, which are low-risk, repeatable and documented in advance.

  • ✓

    Emergency change – requires immediate implementation to resolve a major incident.

    Why this is correct

    Emergency changes address major incidents requiring immediate implementation, bypassing the normal CAB cycle to restore service quickly. Including this type satisfies the stem's constraint by defining a controlled fast-track path with retrospective review, so urgent fixes are not made outside the process.

  • ✓

    Standard change – pre-approved, low risk, follows a defined procedure.

    Why this is correct

    Standard changes are pre-approved, low-risk and follow a documented procedure, so they need no per-instance CAB authorisation. Including this type satisfies the stem's constraint by removing routine, repeatable changes from the approval queue while retaining auditability.

  • ✗

    Major change – requires executive approval and a separate risk assessment.

    Why it's wrong here

    ITIL does not define 'major' as a separate change type; it is typically a category within normal changes.

  • ✓

    Normal change – requires approval from the Change Advisory Board (CAB).

    Why this is correct

    Normal changes carry sufficient risk to require Change Advisory Board assessment and approval before implementation. Including this type satisfies the stem's constraint by ensuring significant changes receive scheduled, documented authorisation, balancing the emergency and standard categories.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.