Worksheets010_Change Management – CompTIA Security+ SY0-701 – 1.3
Total questions: 19
Worksheet time: 10mins
How do changes in a home environment differ from those in a corporate environment?
Home changes impact multiple systems, corporate changes affect only one
Home changes don’t require approval, corporate changes need formal processes
Corporate changes are less risky than home changes
Home changes follow strict approval guidelines
Corporate changes do not require documentation
Why is a formal change control process necessary in an organization?
To allow unrestricted system changes
To increase the complexity of IT operations
To ensure changes are tested, reviewed, and approved before implementation
To prevent employees from using IT resources
To delay necessary system updates
How does change control contribute to system security?
It prevents users from accessing the system
It ensures that only IT staff can make system changes
It helps prevent vulnerabilities by managing updates properly
It eliminates the need for security software
It reduces the number of IT staff needed
What role does change control play in maintaining system stability?
Prevents unauthorized changes that could cause disruptions
Eliminates the need for system updates
Ensures all applications are identical
Reduces the number of users on the system
Blocks any software updates
Why is consistency important in change control?
Ensures all employees make personal changes to systems
Reduces the risk of unexpected failures or incompatibilities
Prevents organizations from updating their systems
Avoids unnecessary documentation
Eliminates the need for IT teams
How does change control help with accountability?
Prevents system administrators from making updates
Ensures all changes are documented and tracked
Stops all software installations
Restricts access to system logs
Removes the need for change requests
In what ways does change control mitigate risks?
Reduces the possibility of system failures
Increases unauthorized changes
Prevents necessary updates
Ensures IT staff can bypass policies
Eliminates documentation requirements
What information should be included in a change request submission?
Reason, scope, affected systems, and schedule
Only the name of the requester
A list of employees impacted
A summary of past system changes
None of the above
Why is risk assessment crucial in the change control process?
To determine potential negative impacts of the change
To eliminate all system updates
To avoid involving stakeholders
To speed up the change approval process
To restrict IT teams from making changes
Who is responsible for approving, modifying, or rejecting a change request?
The IT team
The Change Control Board
The application/data owner
The system users
The CEO
What is the role of the application/data owner in the change control process?
Initiates and verifies system functionality after the change
Approves all changes
Implements and tests system updates
Denies change requests
Monitors security settings
How does the IT team contribute to change control?
Makes unauthorized changes
Implements and tests changes
Rejects all change requests
Restricts user access
Monitors only security updates
What responsibilities does the Change Control Board have?
Approving or denying changes
Implementing system updates
Blocking unauthorized access
Writing code for applications
Monitoring internet usage
Who are stakeholders in the change control process?
Only IT staff
Individuals or departments affected by the change
Only upper management
Only employees who requested the change
None of the above
Why is it important to involve stakeholders in change control decisions?
To gain insights on potential impacts
To slow down the process
To eliminate documentation requirements
To allow unrestricted changes
To block IT staff from making updates
What potential issues can arise from implementing a change?
Downtime, data corruption, or software failures
Increased efficiency
Enhanced system security
Faster application processing
Lower IT costs
How can not making a change lead to security vulnerabilities?
Leaves outdated software open to attacks
Prevents unauthorized changes
Ensures system stability
Reduces IT workload
Blocks all updates
Why should thorough testing be performed before deploying a change?
To detect potential issues before affecting production systems
To speed up implementation
To eliminate the need for documentation
To avoid involving stakeholders
To prevent IT staff from approving changes
How does scheduling changes during low-impact periods help an organization?
Minimizes disruptions to business operations
Increases downtime
Makes testing unnecessary
Blocks user access
Eliminates the need for approvals
