ISO 20000 Certification Change Management 3 — Questions and Answers
Question 1: A change request is submitted but lacks sufficient information to assess its risk. According to ISO 20000, what should happen?
- Return it to the requester for clarification (Correct answer)
- Classify it as a standard change
- Approve it provisionally and review later
- Escalate it directly to emergency CAB
Correct answer: Return it to the requester for clarification
Incomplete change requests must be returned for more information before they can be properly evaluated and authorized.
Question 2: In ISO 20000, which term describes the coordinated activity of moving a tested change from the test environment to the live environment?
- Deployment (Correct answer)
- Change authorization
- Build verification
- Configuration baselining
Correct answer: Deployment
Deployment is the activity that transfers an approved, tested change into the live service environment.
Question 3: ISO 20000 change management requires a remediation plan. When is this plan MOST critical?
- When implementing a high-risk or complex change (Correct answer)
- When conducting a standard pre-approved change
- When closing a successfully completed change
- When drafting the change schedule
Correct answer: When implementing a high-risk or complex change
High-risk changes require a remediation (back-out) plan so the organization can recover if the change fails.
Question 4: Which metric would BEST demonstrate the effectiveness of change management to ISO 20000 auditors?
- Percentage of changes causing incidents (change-related incidents) (Correct answer)
- Total number of change requests submitted
- Average time to raise a change request
- Number of CAB members attending meetings
Correct answer: Percentage of changes causing incidents (change-related incidents)
The rate of change-related incidents directly measures how well change management controls risk and protects service quality.
Question 5: ISO 20000 states that the change management process must interface with which process to ensure infrastructure records stay accurate after a change?
- Configuration management (Correct answer)
- Incident management
- Problem management
- Financial management
Correct answer: Configuration management
Configuration management must be updated after every change to maintain accurate CMDB records reflecting the current state of infrastructure.
Question 6: A post-implementation review (PIR) is conducted after a major change. What is the PRIMARY objective of the PIR?
- Determine whether the change met its objectives and identify lessons learned (Correct answer)
- Authorize the next change in the schedule
- Update the service catalog with new capabilities
- Close all related incidents automatically
Correct answer: Determine whether the change met its objectives and identify lessons learned
The PIR evaluates change outcomes against objectives and captures lessons learned to improve future changes.
Question 7: Under ISO 20000, who bears ultimate accountability for the change management process?
- The process owner (Correct answer)
- The CAB chairperson
- The service desk manager
- The IT director
Correct answer: The process owner
The process owner is accountable for the design, performance, and improvement of the change management process.
A change request is submitted but lacks sufficient information to assess its risk.
According to ISO 20000, what should happen?