Question

Difficulty: Very hardChange Management Processes

A network engineer is preparing to upgrade the core firewall firmware across an enterprise infrastructure to mitigate a critical zero-day vulnerability. Which of the following documentation components must be defined and included in the formal change request prior to submitting it to the Change Advisory Board (CAB)? (Select TWO.)

  1. A risk analysis detailing potential operational impacts and dependenciesAnswer
  2. A documented rollback plan outlining specific steps to revert the system if the upgrade failsAnswer
  3. C
    Post-implementation verification logs confirming successful firmware deployment in production
  4. D
    An emergency change authorization signed exclusively by the helpdesk manager to bypass CAB review

Answer

The formal change request submitted to the CAB must include a risk analysis detailing potential operational impacts and dependencies, as well as a documented rollback plan outlining steps to revert the system if the upgrade fails.
Proper change management governance requires submitting a complete proposal for CAB review prior to implementing any system modifications. Core components required before approval include defining the purpose and scope of change, conducting a comprehensive risk analysis to identify business impact and dependencies, formulating an implementation plan, creating a detailed rollback plan to revert changes if failure occurs, and scheduling user notifications. Conducting a risk analysis and establishing a rollback plan are essential pre-implementation documents.

Step-by-Step Solution

1
Identify the mandatory pre-implementation components of a formal change request submission.
The change request must contain the purpose, scope of change, risk assessment, implementation plan, rollback plan, and end-user notification plan.
CAB approval requires reviewing the complete safety net and potential impacts before authorizing any production change.
2
Evaluate the necessity of a risk analysis.
Risk analysis is verified as a mandatory pre-submission requirement.
It allows the board to evaluate business risk and potential service disruptions.
3
Evaluate the necessity of a rollback plan.
A rollback plan is verified as a mandatory pre-submission requirement.
Having step-by-step restoration procedures ensures systems can quickly recover if the update causes unforeseen instability.
4
Assess incorrect options based on change management lifecycle timing.
Post-implementation logs cannot be generated prior to execution, and helpdesk sign-off cannot bypass formal CAB/ECAB authority.
Testing happens post-deployment, and unauthorized policy bypasses break change control governance.

Key Concept

Change Management Documentation and CAB Submission Requirements
Rate this question