ISC · domain
Secure Operations Change Management And Disposal
Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Secure Operations Change Management And Disposal practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Secure Operations Change Management And Disposal questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Secure Operations Change Management And Disposal
Secure Operations Change Management And Disposal questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Secure Operations Change Management And Disposal exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Secure Operations Change Management And Disposal questions (28)
Click any question to see the full explanation, or start a practice session above.
You are managing a change request in ServiceNow. To ensure compliance with the RFC process for a security patch, which state transition is mandatory before implementation?
Hard2In a Kubernetes environment, you are updating a security sidecar container. Which deployment strategy ensures zero downtime while maintaining security posture?
Medium3Which THREE elements are essential in a Change Management policy?
Medium4Which THREE strategies are used to mitigate risk during a production software change?
Hard5When conducting a security impact analysis for a system change in a Federal environment, what is the primary purpose of reviewing the FIPS 199 categorization?
Medium6Which TWO actions should be included in a secure decommissioning process for a physical server?
Medium7Which TWO criteria are used to determine if a change request must be reviewed by the Change Advisory Board (CAB)?
Medium8Which document outlines the specific security steps to be taken when a workstation reaches its end-of-life?
Easy9Which command line utility is used on Linux to verify the integrity of binary files during a maintenance patch update?
Medium10You are utilizing Terraform to manage infrastructure as code. To ensure security-critical changes are not committed to production without authorization, which feature should you implement?
Hard11You are performing a 'Sanitization' of a drive according to NIST 800-88. If the drive is 'Clear' status, what does this imply?
Medium12What is the primary function of a Change Advisory Board (CAB) in an ITIL-based environment?
Easy13What is the first step when preparing a system for secure disposal?
Easy14You are reviewing a Change Management plan for an ICS (Industrial Control System). What is the most critical risk during the 'Implement' phase?
Medium15An administrator needs to wipe a decommissioned laptop hard drive. Which method meets the NIST 800-88 'Purge' standard for magnetic media?
Easy16Which TWO factors must be assessed when determining if a change is 'Emergency' versus 'Standard'?
Medium17You are managing the lifecycle of an enterprise-level cryptographic key. What is the most critical step prior to key decommissioning?
Hard18Which type of change is typically excluded from a formal Change Advisory Board review process?
Easy19You are decommissioning an AWS EBS volume containing sensitive data. To comply with NIST SP 800-88, which action is required after logical deletion?
Medium20When managing a security-sensitive change in a regulated environment, why is 'Separation of Duties' applied to the 'Build' and 'Deploy' roles?
Hard21When managing decommissioning of a cloud-native application, which document must be updated to reflect the removal of security controls?
Medium22A legacy database must be decommissioned. You need to ensure the data is retrievable for 7 years for regulatory compliance. Which strategy is most secure?
Medium23You are configuring a CI/CD pipeline in GitLab to ensure security-critical changes are verified. Which mechanism ensures that only authorized engineers can merge changes to the master branch?
Medium24You are configuring a secure baseline for a server migration. Which NIST SP 800-53 control category covers 'System and Services Acquisition' regarding the maintenance of security-critical configurations?
Hard25Which THREE items should be included in a Post-Implementation Review (PIR) for a security change?
Hard26Which THREE technologies are acceptable for the secure disposal of solid-state drives (SSDs)?
Hard27Which TWO aspects of a system's lifecycle must be documented in the decommission plan?
Medium28When disposing of SSDs that contain PII, why is traditional degaussing ineffective?
HardOther domains
All ISC exam domains
Frequently asked questions
- What does the Secure Operations Change Management And Disposal domain cover on the ISC exam?
- Secure Operations Change Management And Disposal questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 28 Secure Operations Change Management And Disposal questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Operations Change Management And Disposal questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.