After CAB Approval: The Next Step is Testing in a Staging Environment
During a change management process, the Change Advisory Board (CAB) approves a high-risk change. What is the NEXT step according to standard change management?
Quick Answer
Testing the change in a staging environment is the correct next step because CAB approval only confirms that the change has been reviewed and authorized to proceed; it doesn't confirm that the change actually works as intended or won't cause unexpected problems once applied. Standard change management processes, such as those described by ITIL, treat approval and validation as separate gates: approval addresses whether the change should happen from a risk, business, and scheduling standpoint, while testing addresses whether the change will actually function correctly and safely when implemented. Skipping straight from approval to production implementation would mean the first real test of a high-risk change happens in the live environment, where any flaw discovered has immediate, potentially severe consequences for users and business operations. Staging exists specifically to catch those problems in an environment that mirrors production closely enough to be meaningful, but where failures are contained and reversible. This sequencing, approve, then test, then implement, is a deliberate risk-reduction structure, and it becomes even more important the higher the risk classification of the change, which is exactly the situation described here. When a question asks what happens immediately after CAB approval for a high-risk change, look for validation or testing steps rather than jumping straight to production deployment.
⚠ Common exam trap
Test-takers frequently confuse the order of steps: candidates often think approval directly leads to implementation, but standard change management mandates testing in a controlled environment first to prevent production incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test the change in a staging environment
After CAB approval, the next step is to test the change in a staging environment to validate its functionality and identify potential issues before production deployment. This aligns with standard change management processes (e.g., ITIL) where testing follows approval to ensure the change does not disrupt operations. Immediate implementation without testing would bypass risk mitigation, making D the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement the change immediately
Why it's wrong here
Implementation should occur after testing and rollback planning.
- ✗
Document the rollback plan
Why it's wrong here
Rollback plan should be documented before approval, not after.
- ✗
Perform a post-implementation review
Why it's wrong here
This occurs after implementation, not before.
- ✓
Test the change in a staging environment
Why this is correct
Correct. Testing is crucial before production deployment.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A change request to update a firewall rule has been submitted. After impact assessment, the change is approved by the Change Advisory Board (CAB). What is the NEXT step in the change management process?
medium- A.Perform post-implementation review
- B.Develop a rollback plan
- C.Implement the change in production
- ✓ D.Test the change in a staging environment
Why D: After CAB approval, the next step is to test the change in a staging environment that mirrors production. This validates the firewall rule change does not introduce security gaps or performance issues before deployment. Testing in staging ensures the rule syntax, order, and interaction with existing rules are correct, preventing unintended access or denial of service.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.