SSCP Security Operations and Administration Practice Question
Which of the following is the correct order of steps in the change management process?
⚠ Common exam trap
The trap is that candidates reorder CAB approval before impact assessment because approval 'feels' like it should come early — but the CAB needs the impact assessment as its input, so assessment must precede approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change request, impact assessment, CAB approval, testing, implementation, post-implementation review
The standard change management lifecycle begins with a formal change request, followed by an impact/risk assessment so the CAB has the information needed to evaluate the change. Only after that assessment does the CAB approve or reject, then testing occurs in a non-production environment, then implementation, and finally a post-implementation review to confirm success and capture lessons learned. This sequence ensures decisions are made with full information and that changes are validated before touching production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change request, impact assessment, CAB approval, testing, implementation, post-implementation review
Why this is correct
The sequence begins with a formal change request, followed by impact assessment, approval from the change advisory board, testing, implementation, and finally a post-implementation review to confirm the change achieved its objective without adverse effects.
- ✗
Change request, CAB approval, impact assessment, testing, implementation, post-implementation review
Why it's wrong here
Impact assessment must precede CAB approval, since the board needs the assessed risk and affected systems before authorising. This option places approval before assessment, so the CAB decides without that information. It is tempting because a change request does legitimately open the process.
- ✗
Impact assessment, change request, CAB approval, testing, implementation, post-implementation review
Why it's wrong here
A change request must be raised before it can be assessed; nothing exists to assess otherwise. This option reverses those first two steps. It is tempting because impact assessment is genuinely the second step, immediately after the request is logged and before CAB review.
- ✗
Change request, testing, impact assessment, CAB approval, implementation, post-implementation review
Why it's wrong here
Testing follows impact assessment and CAB approval, not the request; the CAB must authorise before test resources are consumed. This option tests before both. It is tempting because testing is a real stage that does occur before implementation in the correct sequence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.