CISA Practice Question: Information Systems Acquisition, Development, and Implementation
Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Normal change
Normal changes are those that are not pre-approved or emergency. They require assessment and approval by the CAB to evaluate risks and impacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Emergency change
Why it's wrong here
Emergency changes bypass the CAB's scheduled review, being authorised instead by the Emergency Change Advisory Board (ECAB) or a delegated approver to restore service quickly. It is tempting because emergency changes still demand formal approval, but that authority sits with the ECAB under compressed timescales, not the standard CAB.
- ✓
Normal change
Why this is correct
Normal changes follow the full assessment and authorisation path, so they require CAB approval before implementation. Standard changes are pre-authorised by a defined procedure, and emergency changes use a separate expedited route, typically with retrospective CAB review.
- ✗
Standard change
Why it's wrong here
Standard changes are pre-authorised: the change model is approved in advance, so individual instances are implemented without CAB review. It is tempting because standard changes are still formally documented and controlled, but their defining characteristic is a pre-approved, repeatable procedure, which is precisely why per-change CAB approval is unnecessary.
- ✗
All changes
Why it's wrong here
Standard, low-risk changes follow pre-approved or normal change processes that do not require CAB review, so blanket approval is inaccurate. It is tempting because CAB oversight sounds comprehensive, but it would be correct only for significant normal changes, not emergency or standard ones.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.