Courseiva
Security Operations →mediumMultiple Choice

CISSP Security Operations Practice Question

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

⚠ Common exam trap

CISSP often tests the scope of CAB authority — candidates pick 'approve all changes' because it sounds comprehensive, but the CAB only reviews significant/high-risk changes; standard changes are pre-authorized and bypass the CAB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide oversight and approval for significant changes

The Change Advisory Board (CAB) exists to review, assess, and approve significant changes before they are deployed, providing governance and risk oversight across the IT environment. Its primary purpose is oversight and approval, not hands-on implementation or incident review. This aligns with ITIL change enablement practices, where the CAB advises the change authority on risk and impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To provide oversight and approval for significant changes

    Why this is correct

    The Change Advisory Board (CAB) primarily serves as a governance body responsible for evaluating and authorizing significant changes to IT services and infrastructure. This oversight ensures that all high-impact or high-risk modifications are thoroughly assessed for potential security implications, operational disruptions, and resource requirements before implementation. Their approval process is crucial for maintaining system stability, security posture, and compliance.

  • ✗

    To implement changes as requested by management

    Why it's wrong here

    The Change Advisory Board (CAB) is not responsible for the physical or technical implementation of changes. Its role is strictly advisory and approval-based, focusing on the strategic assessment and authorization of proposed modifications. The actual execution, scheduling, and deployment of approved changes are typically handled by dedicated change management teams or operational staff, who follow the procedures established by the CAB's approval.

  • ✗

    To review security incidents after they occur

    Why it's wrong here

    Reviewing security incidents after they occur falls under the domain of incident response and post-incident analysis teams, not the Change Advisory Board (CAB). The CAB's mandate is proactive, focusing on mitigating risks *before* changes are introduced into the production environment. Its purpose is to prevent incidents by carefully scrutinizing proposed changes, rather than reacting to or analyzing events that have already transpired.

  • ✗

    To approve all changes to the production environment

    Why it's wrong here

    While the Change Advisory Board (CAB) plays a critical role in change control, it does not approve *all* changes to the production environment. Many routine, low-risk, pre-approved 'standard changes' or urgent 'emergency changes' often bypass full CAB review to expedite necessary actions. The CAB typically concentrates its efforts on 'normal changes' that are significant, complex, or carry higher potential risk, ensuring efficient resource allocation and focused risk management.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.