Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?

⚠ Common exam trap

The trap is confusing the CAB's governance role with operational execution; candidates may pick 'implement the change' because the scenario describes a technical task, but the CAB never implements — it reviews and approves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review and approve the change

The CAB's primary role is to review and approve (or reject) proposed changes by assessing risk, impact, and readiness. In this scenario, the change is a normal change that has been risk-assessed as low impact, so the CAB's most likely action is to review and approve it for implementation during the maintenance window. The CAB does not implement changes, nor does it arbitrarily reject or defer changes that are properly justified and assessed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Review and approve the change

    Why this is correct

    Normal changes require CAB review and authorisation before implementation. Even though the patch is low impact, the reboot and database scope mean the CAB must review and approve it, satisfying the stem's normal-category constraint rather than auto-approving it as standard.

  • ✗

    Implement the change directly

    Why it's wrong here

    The CAB authorises and schedules changes; it does not execute them. Direct implementation bypasses the change management process, removing the controlled handover to database administrators who perform the reboot. A CAB would implement directly only in a small organisation where the same staff both approve and carry out changes.

  • ✗

    Reject the change as unnecessary

    Why it's wrong here

    Rejecting the patch leaves a known vulnerability unaddressed, contradicting the low-impact risk assessment that supports proceeding. Rejection fits changes whose risk or business disruption outweighs their benefit, not a security patch requiring a brief reboot. The CAB's role is to authorise, not refuse.

  • ✗

    Defer the change to the next release cycle

    Why it's wrong here

    Deferring to the next release cycle delays a security patch that has already been risk-assessed as low impact, leaving the database exposed unnecessarily. Release-cycle batching suits non-urgent enhancements, not remediating known vulnerabilities, so the CAB should authorise the patch rather than postpone it.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.