CISSP Security Operations Practice Question
Which of the following is the primary purpose of a Change Advisory Board (CAB)?
⚠ Common exam trap
CISSP often tests the scope of CAB authority — candidates pick 'approve all changes' because it sounds comprehensive, but the CAB only reviews significant/high-risk changes; standard changes are pre-authorized and bypass the CAB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide oversight and approval for significant changes
The Change Advisory Board (CAB) exists to review, assess, and approve significant changes before they are deployed, providing governance and risk oversight across the IT environment. Its primary purpose is oversight and approval, not hands-on implementation or incident review. This aligns with ITIL change enablement practices, where the CAB advises the change authority on risk and impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To provide oversight and approval for significant changes
Why this is correct
The Change Advisory Board (CAB) primarily serves as a governance body responsible for evaluating and authorizing significant changes to IT services and infrastructure. This oversight ensures that all high-impact or high-risk modifications are thoroughly assessed for potential security implications, operational disruptions, and resource requirements before implementation. Their approval process is crucial for maintaining system stability, security posture, and compliance.
- ✗
To implement changes as requested by management
Why it's wrong here
The Change Advisory Board (CAB) is not responsible for the physical or technical implementation of changes. Its role is strictly advisory and approval-based, focusing on the strategic assessment and authorization of proposed modifications. The actual execution, scheduling, and deployment of approved changes are typically handled by dedicated change management teams or operational staff, who follow the procedures established by the CAB's approval.
- ✗
To review security incidents after they occur
Why it's wrong here
Reviewing security incidents after they occur falls under the domain of incident response and post-incident analysis teams, not the Change Advisory Board (CAB). The CAB's mandate is proactive, focusing on mitigating risks *before* changes are introduced into the production environment. Its purpose is to prevent incidents by carefully scrutinizing proposed changes, rather than reacting to or analyzing events that have already transpired.
- ✗
To approve all changes to the production environment
Why it's wrong here
While the Change Advisory Board (CAB) plays a critical role in change control, it does not approve *all* changes to the production environment. Many routine, low-risk, pre-approved 'standard changes' or urgent 'emergency changes' often bypass full CAB review to expedite necessary actions. The CAB typically concentrates its efforts on 'normal changes' that are significant, complex, or carry higher potential risk, ensuring efficient resource allocation and focused risk management.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.