SY0-701 - General Security Concepts - Section 1.3

Explain the importance of change management processes and their impact on security.

Describe how a formal change management process uses approval workflows, impact analysis, and a backout plan to reduce the risk that configuration changes introduce new vulnerabilities. Recognise the roles of maintenance windows and version control in ensuring changes are scheduled safely and can be audited or reversed.

approval processimpact analysisbackout planmaintenance windowversion control

Practice question for this objective

Free sampleGeneral Security Conceptsmedium

Which statement best describes the primary purpose of an impact analysis within a formal change management process?

  • AIt documents the exact sequence of commands an engineer will execute on production systems during the approved maintenance window.
  • BIt evaluates the technical, operational, and security consequences of a proposed change so the change advisory board can decide whether to approve it. Correct
  • CIt records the names of the staff who approved the change request and the timestamps at which each approval was registered.
  • DIt provides a step by step procedure for reverting the production environment if the deployed change behaves unexpectedly after go live.
Recognise that impact analysis is the pre approval assessment of a change's technical, operational, and security consequences. Impact analysis is the structured pre approval activity in change management that identifies what systems, users, controls, and obligations the change will affect. By forcing dependencies, downtime, and security exposure to be enumerated before the change advisory board votes, it lets the board make a risk informed decision and distinguishes itself from the runbook, the approval log, and the backout plan.

Why A is wrong: This describes the implementation plan or runbook, which is a separate artefact. An impact analysis precedes the runbook and asks whether the change should be done at all, not the keystrokes used to do it.

Why B is correct: Impact analysis exists to surface dependencies, downtime, regulatory effects, and security exposure of the proposed change before approval, giving the board a defensible basis for the decision.

Why C is wrong: This is the approval log or change record, not impact analysis. Approval metadata supports accountability but does not assess the consequences of the change itself.

Why D is wrong: That is the definition of a backout plan, which is a different mandatory artefact within change management. A good backout plan does not analyse impact; it executes a return to the prior known good state.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all General Security Concepts objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.