Courseiva

ISC · domain

Secure Operations Change Management And Disposal

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Secure Operations Change Management And Disposal practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

28 questions5 easy14 medium9 hard

Focused practice

Practice Secure Operations Change Management And Disposal questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Secure Operations Change Management And Disposal

Secure Operations Change Management And Disposal questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Secure Operations Change Management And Disposal exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Secure Operations Change Management And Disposal questions (28)

Click any question to see the full explanation, or start a practice session above.

1

You are managing a change request in ServiceNow. To ensure compliance with the RFC process for a security patch, which state transition is mandatory before implementation?

Hard
2

In a Kubernetes environment, you are updating a security sidecar container. Which deployment strategy ensures zero downtime while maintaining security posture?

Medium
3

Which THREE elements are essential in a Change Management policy?

Medium
4

Which THREE strategies are used to mitigate risk during a production software change?

Hard
5

When conducting a security impact analysis for a system change in a Federal environment, what is the primary purpose of reviewing the FIPS 199 categorization?

Medium
6

Which TWO actions should be included in a secure decommissioning process for a physical server?

Medium
7

Which TWO criteria are used to determine if a change request must be reviewed by the Change Advisory Board (CAB)?

Medium
8

Which document outlines the specific security steps to be taken when a workstation reaches its end-of-life?

Easy
9

Which command line utility is used on Linux to verify the integrity of binary files during a maintenance patch update?

Medium
10

You are utilizing Terraform to manage infrastructure as code. To ensure security-critical changes are not committed to production without authorization, which feature should you implement?

Hard
11

You are performing a 'Sanitization' of a drive according to NIST 800-88. If the drive is 'Clear' status, what does this imply?

Medium
12

What is the primary function of a Change Advisory Board (CAB) in an ITIL-based environment?

Easy
13

What is the first step when preparing a system for secure disposal?

Easy
14

You are reviewing a Change Management plan for an ICS (Industrial Control System). What is the most critical risk during the 'Implement' phase?

Medium
15

An administrator needs to wipe a decommissioned laptop hard drive. Which method meets the NIST 800-88 'Purge' standard for magnetic media?

Easy
16

Which TWO factors must be assessed when determining if a change is 'Emergency' versus 'Standard'?

Medium
17

You are managing the lifecycle of an enterprise-level cryptographic key. What is the most critical step prior to key decommissioning?

Hard
18

Which type of change is typically excluded from a formal Change Advisory Board review process?

Easy
19

You are decommissioning an AWS EBS volume containing sensitive data. To comply with NIST SP 800-88, which action is required after logical deletion?

Medium
20

When managing a security-sensitive change in a regulated environment, why is 'Separation of Duties' applied to the 'Build' and 'Deploy' roles?

Hard
21

When managing decommissioning of a cloud-native application, which document must be updated to reflect the removal of security controls?

Medium
22

A legacy database must be decommissioned. You need to ensure the data is retrievable for 7 years for regulatory compliance. Which strategy is most secure?

Medium
23

You are configuring a CI/CD pipeline in GitLab to ensure security-critical changes are verified. Which mechanism ensures that only authorized engineers can merge changes to the master branch?

Medium
24

You are configuring a secure baseline for a server migration. Which NIST SP 800-53 control category covers 'System and Services Acquisition' regarding the maintenance of security-critical configurations?

Hard
25

Which THREE items should be included in a Post-Implementation Review (PIR) for a security change?

Hard
26

Which THREE technologies are acceptable for the secure disposal of solid-state drives (SSDs)?

Hard
27

Which TWO aspects of a system's lifecycle must be documented in the decommission plan?

Medium
28

When disposing of SSDs that contain PII, why is traditional degaussing ineffective?

Hard

Frequently asked questions

What does the Secure Operations Change Management And Disposal domain cover on the ISC exam?
Secure Operations Change Management And Disposal questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 28 Secure Operations Change Management And Disposal questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure Operations Change Management And Disposal questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issep ISC2-ISSEP secure operations change management and disposal Practice Questions