A network engineer is preparing to upgrade the core firewall firmware across an enterprise infrastructure to mitigate a critical zero-day vulnerability. Which of the following documentation components must be defined and included in the formal change request prior to submitting it to the Change Advisory Board (CAB)? (Select TWO.)
- A risk analysis detailing potential operational impacts and dependenciesAnswer
- A documented rollback plan outlining specific steps to revert the system if the upgrade failsAnswer
- CPost-implementation verification logs confirming successful firmware deployment in production
- DAn emergency change authorization signed exclusively by the helpdesk manager to bypass CAB review
Answer
The formal change request submitted to the CAB must include a risk analysis detailing potential operational impacts and dependencies, as well as a documented rollback plan outlining steps to revert the system if the upgrade fails.
Proper change management governance requires submitting a complete proposal for CAB review prior to implementing any system modifications. Core components required before approval include defining the purpose and scope of change, conducting a comprehensive risk analysis to identify business impact and dependencies, formulating an implementation plan, creating a detailed rollback plan to revert changes if failure occurs, and scheduling user notifications. Conducting a risk analysis and establishing a rollback plan are essential pre-implementation documents.
Step-by-Step Solution
Key Concept
Change Management Documentation and CAB Submission Requirements