SY0-701 - General Security Concepts (12% of the exam) - Section 1.3

Explain the importance of change management processes and their impact on security.

Describe how a formal change management process uses approval workflows, impact analysis, and a backout plan to reduce the risk that configuration changes introduce new vulnerabilities. Recognise the roles of maintenance windows and version control in ensuring changes are scheduled safely and can be audited or reversed.

approval processimpact analysisbackout planmaintenance windowversion control

Practice question for this objective

Free sampleGeneral Security Conceptsmedium

Which statement best describes the primary purpose of an impact analysis within a formal change management process?

  • AIt documents the exact sequence of commands an engineer will execute on production systems during the approved maintenance window.
  • BIt evaluates the technical, operational, and security consequences of a proposed change so the change advisory board can decide whether to approve it. Correct
  • CIt records the names of the staff who approved the change request and the timestamps at which each approval was registered.
  • DIt provides a step by step procedure for reverting the production environment if the deployed change behaves unexpectedly after go live.
Recognise that impact analysis is the pre approval assessment of a change's technical, operational, and security consequences. Impact analysis is the structured pre approval activity in change management that identifies what systems, users, controls, and obligations the change will affect. By forcing dependencies, downtime, and security exposure to be enumerated before the change advisory board votes, it lets the board make a risk informed decision and distinguishes itself from the runbook, the approval log, and the backout plan.

Why A is wrong: This describes the implementation plan or runbook, which is a separate artefact. An impact analysis precedes the runbook and asks whether the change should be done at all, not the keystrokes used to do it.

Why B is correct: Impact analysis exists to surface dependencies, downtime, regulatory effects, and security exposure of the proposed change before approval, giving the board a defensible basis for the decision.

Why C is wrong: This is the approval log or change record, not impact analysis. Approval metadata supports accountability but does not assess the consequences of the change itself.

Why D is wrong: That is the definition of a backout plan, which is a different mandatory artefact within change management. A good backout plan does not analyse impact; it executes a return to the prior known good state.

See more SY0-701 practice questions, answers explained.

Exam traps in General Security Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • It is a calendar period reserved for unscheduled emergency changes that bypass the normal change advisory board review and approval cycle.

    Why it is wrong: Emergency changes follow an expedited approval path, not a standing maintenance window. Conflating the two would undermine the approval discipline that maintenance windows are meant to support.

  • Obtaining a second technical approver signature on the existing change ticket prior to the cutover window

    Why it is wrong: Additional approver sign-off increases accountability for the decision but does not itself reveal which services or dependencies the firewall change could disrupt.

  • Increasing the frequency of vulnerability scans so high severity findings are detected earlier in the month

    Why it is wrong: More frequent scanning surfaces vulnerabilities sooner but does not stop an administrator from bypassing the documented approval workflow when applying a fix.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.