SSCP Security Operations and Administration Practice Question
Which THREE of the following are valid steps in the change management process? (Select THREE)
⚠ Common exam trap
It's easy for candidates to confuse operational security activities like vulnerability scanning or configuration updates with formal change management process steps, which are specifically about the lifecycle of a change request from submission through review.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Post-implementation review
Option E (Change request submission) is correct because the change management process formally begins when a Request for Change (RFC) is submitted and logged, often via a ticketing or ITSM system, so the change can be reviewed and authorized. Option D (Impact assessment) is correct because after the RFC is raised, the change advisory board or reviewers evaluate risk, scope, affected systems, and potential downtime to decide whether the change should be approved. Option A (Post-implementation review) is correct because after the change is deployed, the process includes verifying that it achieved its objective, did not cause unintended issues, and capturing lessons learned for future changes. Option B (Vulnerability scanning) is not a change management step; it is a security assessment activity typically performed under vulnerability management, even though its findings may trigger an RFC. Option C (Baseline configuration update) is not a step in the change management process itself; updating the configuration baseline is a configuration management activity that occurs after an approved change is implemented.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Post-implementation review
Why this is correct
A post-implementation review closes the change management lifecycle by verifying the change achieved its intended outcome and identifying any unanticipated effects. It is a recognised procedural step, distinct from implementation itself, and satisfies the stem's requirement for a valid change process stage.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning identifies weaknesses and feeds risk assessment; it is not a change management step, which covers requesting, approving, implementing and reviewing changes. It tempts because scan findings often trigger change requests, but scanning itself sits in vulnerability management.
- ✗
Baseline configuration update
Why it's wrong here
Updating the baseline configuration is a configuration management activity performed after a change is approved and implemented, not a change management process step itself. It tempts because baselines and changes are closely linked, but the process covers request, approval, implementation and review.
- ✓
Impact assessment
Why this is correct
Impact assessment evaluates the risk, scope and resource implications of a proposed change before approval, feeding the change advisory board's decision. It is a distinct procedural step in change management, satisfying the stem's requirement for a valid process stage.
- ✓
Change request submission
Why this is correct
Change request submission formally initiates the change management process, documenting the proposed alteration for review and approval. It is the recognised entry point step, distinct from assessment and review, satisfying the stem's requirement for a valid process stage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.