ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a scheduled change window, a CGRC practitioner is preparing to promote an approved update that tightens TLS cipher suites for a customer-facing web service. According to sound change-management practice, which activity must be completed before moving the change out of the isolated test environment into production?
Complete the post-implementation review and submit the findings to the change control board for archival.
Disable automated monitoring during deployment so transient alerts do not trigger incident response.
Verify that the change met documented test-exit criteria and that a complete, approved rollback procedure is available.
Obtain written confirmation from affected end users that they have received the deployment notification.
Before a change is promoted from test to production, change-management best practice calls for two key assurances: 1) objective evidence that the change has met its documented test-exit or acceptance criteria, and 2) a documented, approved rollback (back-out) procedure that can restore the system to its last known good state if the deployment causes issues. Frameworks such as NIST SP 800-128 and ITIL highlight the importance of both verified testing and preparation of fallback actions (the extent of the rollback documentation may be risk-based in NIST guidance). Post-implementation reviews, user notifications, or temporarily suppressing monitoring are valid activities but occur after deployment or serve other purposes and therefore are not prerequisites for releasing the change.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-128 and how does it apply to change management?
Open an interactive chat with Bash
Why are test-exit criteria essential in change management?
Open an interactive chat with Bash
What is a rollback procedure, and why must it be documented?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .