Courseiva

SSCP Security Operations and Administration Practice Question

Which of the following is the correct order of steps in the change management process?

⚠ Common exam trap

The trap is that candidates reorder CAB approval before impact assessment because approval 'feels' like it should come early — but the CAB needs the impact assessment as its input, so assessment must precede approval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change request, impact assessment, CAB approval, testing, implementation, post-implementation review

The standard change management lifecycle begins with a formal change request, followed by an impact/risk assessment so the CAB has the information needed to evaluate the change. Only after that assessment does the CAB approve or reject, then testing occurs in a non-production environment, then implementation, and finally a post-implementation review to confirm success and capture lessons learned. This sequence ensures decisions are made with full information and that changes are validated before touching production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Change request, impact assessment, CAB approval, testing, implementation, post-implementation review

    Why this is correct

    The sequence begins with a formal change request, followed by impact assessment, approval from the change advisory board, testing, implementation, and finally a post-implementation review to confirm the change achieved its objective without adverse effects.

  • ✗

    Change request, CAB approval, impact assessment, testing, implementation, post-implementation review

    Why it's wrong here

    Impact assessment must precede CAB approval, since the board needs the assessed risk and affected systems before authorising. This option places approval before assessment, so the CAB decides without that information. It is tempting because a change request does legitimately open the process.

  • ✗

    Impact assessment, change request, CAB approval, testing, implementation, post-implementation review

    Why it's wrong here

    A change request must be raised before it can be assessed; nothing exists to assess otherwise. This option reverses those first two steps. It is tempting because impact assessment is genuinely the second step, immediately after the request is logged and before CAB review.

  • ✗

    Change request, testing, impact assessment, CAB approval, implementation, post-implementation review

    Why it's wrong here

    Testing follows impact assessment and CAB approval, not the request; the CAB must authorise before test resources are consumed. This option tests before both. It is tempting because testing is a real stage that does occur before implementation in the correct sequence.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.