Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

⚠ Common exam trap

The CISSP exam often tests the distinction between operational roles (SOC, Incident Response) and governance/approval bodies (CAB), leading candidates to confuse real-time monitoring functions with change authorization responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change Advisory Board (CAB)

The Change Advisory Board (CAB) is the formal group within ITIL-based change management responsible for reviewing, assessing, and approving major or high-risk changes. Major changes typically require a CAB meeting to evaluate impact, resource requirements, and rollback plans before authorization. This ensures changes do not introduce security vulnerabilities or disrupt critical operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Project management office

    Why it's wrong here

    The Project Management Office (PMO) is responsible for standardizing project-related governance processes and facilitating the sharing of resources, methodologies, and tools across an organization's projects. While projects often introduce significant changes, the PMO's mandate is to oversee the execution and success of projects themselves, not the granular approval or management of individual operational or infrastructure changes to existing systems. Their focus is on strategic project portfolio alignment and delivery.

  • Incident response team

    Why it's wrong here

    The Incident Response Team (IRT) is a specialized group dedicated to detecting, analyzing, containing, eradicating, recovering from, and post-incident reviewing security incidents or system outages. Their primary function is reactive, focusing on restoring normal operations and mitigating harm after an event has occurred. This critical role is distinct from the proactive, planned process of evaluating and authorizing proposed changes to systems or services before they are implemented.

  • Change Advisory Board (CAB)

    Why this is correct

    The Change Advisory Board (CAB) is a crucial component of a robust change management process, specifically tasked with reviewing, assessing, prioritizing, and authorizing proposed changes to an organization's IT services and infrastructure. Comprising diverse stakeholders, the CAB ensures that all potential impacts, risks, and resource requirements are thoroughly evaluated, including security implications, before a change is approved for implementation. This structured review minimizes adverse effects and maintains system stability.

  • Security operations center

    Why it's wrong here

    The Security Operations Center (SOC) is responsible for continuously monitoring an organization's information systems for security incidents, analyzing threats, and coordinating responses to protect assets. While the SOC plays a vital role in ensuring the security of systems after changes are implemented, and may provide input on security risks during the change process, its core function does not involve the formal approval, scheduling, or overall governance of the change management process itself. Their focus is on threat detection and response.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.