A cloud administrator is preparing to update the signing certificate for an enterprise Single Sign-On (SSO) identity federation service. The administrator has documented the purpose of the change, defined the specific scope, performed a comprehensive risk analysis, and scheduled the maintenance window during off-peak hours. Which of the following elements MUST also be documented and included in the change request prior to submitting it for Change Advisory Board (CAB) approval?
- A backout plan detailing explicit procedures to revert to the existing certificate if authentication fails post-deploymentAnswer
- BFormal written certification from the third-party Certificate Authority authorizing the maintenance window timeframe
- CResults from implementing the certificate update directly on the live production identity provider prior to board review
- DAn automated script configured to terminate all active employee domain sessions immediately upon submitting the proposal
Answer
A backout plan detailing explicit procedures to revert to the existing certificate if authentication fails post-deployment
The correct answer emphasizes the necessity of a backout (rollback) plan. Every formal change request submitted to a Change Advisory Board (CAB) must contain a clear, step-by-step procedure to reverse the change and restore baseline functionality if errors or service disruptions occur after implementation.
Step-by-Step Solution
Key Concept
Standard Change Management Documentation Requirements