ISO 20000 Certification Change Management 2 — Questions and Answers
Question 1: In ISO 20000-1, which body is responsible for approving changes that have significant risk or broad organizational impact?
- Change Advisory Board (CAB) (Correct answer)
- Service Desk
- Problem Manager
- Configuration Manager
Correct answer: Change Advisory Board (CAB)
The Change Advisory Board (CAB) is convened to evaluate, authorize, or escalate high-risk or high-impact changes.
Question 2: An emergency change is deployed, but the post-implementation review reveals the change caused a service outage. What is the FIRST action according to ISO 20000 change management?
- Initiate a rollback and raise an incident (Correct answer)
- Close the change record immediately
- Update the change schedule
- Notify the CAB of the failure
Correct answer: Initiate a rollback and raise an incident
ISO 20000 requires restoring service as soon as possible, so initiating rollback and raising an incident is the correct first action.
Question 3: Which document in ISO 20000 change management formally records every authorized change along with its implementation results?
- Change record (Correct answer)
- Service improvement plan
- Release policy
- Configuration baseline
Correct answer: Change record
A change record captures the full lifecycle of a change from request through closure, including results.
Question 4: ISO 20000 requires that changes be categorized. Which factor PRIMARILY drives the categorization of a change?
- Risk and impact assessment (Correct answer)
- The number of CIs affected
- The requester's seniority
- Time available to implement
Correct answer: Risk and impact assessment
Risk and impact are the primary factors used to categorize changes into standard, normal, or emergency types.
Question 5: A service provider wants to implement changes without disrupting agreed service levels. Which ISO 20000 process must be consulted when scheduling changes?
- Service level management (Correct answer)
- Capacity management
- Supplier management
- Availability management
Correct answer: Service level management
Service level management defines the agreed service windows and must be consulted to avoid breaching SLAs during change implementation.
Question 6: Under ISO 20000, what is the purpose of a 'change freeze'?
- To prevent changes during periods of high business risk or critical operations (Correct answer)
- To allow time for auditing all pending changes
- To update the configuration management database
- To retire obsolete change records
Correct answer: To prevent changes during periods of high business risk or critical operations
A change freeze prohibits non-emergency changes during critical business periods to protect service stability.
Question 7: Which ISO 20000 requirement ensures that a change does not introduce unauthorized configuration items into the live environment?
- Integration between change management and configuration management (Correct answer)
- The release policy
- Incident management escalation
- Service continuity planning
Correct answer: Integration between change management and configuration management
Change and configuration management integration ensures only authorized and correctly recorded CIs are introduced through the change process.
In ISO 20000-1, which body is responsible for approving changes that have significant risk or broad organizational impact?