CompTIA Security+ (SY0-701)General Security ConceptsMedium

During a change management review, a change advisory board rejects a proposed emergency patch deployment because the request does not include a documented plan for reverting the system if the patch causes failures. Which element is missing from the request?

  1. AImpact analysis
  2. BMaintenance window
  3. CStakeholder approval
  4. DRollback plan
Show answer & explanation

Correct answer: D. Rollback plan

A rollback plan describes how to undo a change and restore the previous known-good state if the change causes problems; its absence is a common reason change requests are rejected.

Why the other options are wrong

  • A. Impact analysis evaluates expected effects of the change, not how to reverse it.
  • B. A maintenance window defines when the change occurs, not how to reverse it.
  • C. Stakeholder approval is about sign-off, not technical reversal steps.

Rollback Plan

A documented procedure to revert a system to its prior state if a change causes unexpected issues.

  • Required component of formal change management process
  • Reduces risk of prolonged outages from failed changes
  • Should be tested prior to change implementation when possible

Memory trick: No rollback, no go-back

More General Security Concepts questions