← All CSM Flashcard Decks

CSM Software Configuration & Change Management Flashcards

6 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CSM Software Configuration & Change Management flashcards as text
  1. What is the purpose of a post-implementation review (PIR) after a change is deployed?

    Answer: To evaluate whether the change achieved its objectives and identify lessons learned

    A PIR assesses the success of the implemented change, identifies any unintended consequences, and captures lessons learned to improve future change processes.

  2. In a CI/CD pipeline, which configuration management practice ensures that the exact same build can be reproduced at any time?

    Answer: Immutable artifacts with version-tagged builds stored in an artifact repository

    Storing immutable, version-tagged build artifacts in a repository (e.g., Artifactory, Nexus) ensures any prior build can be exactly reproduced and deployed.

  3. Which of the following BEST defines 'configuration identification' in software CM?

    Answer: Assigning unique identifiers and attributes to all configuration items to enable tracking

    Configuration identification establishes the naming, labeling, and numbering conventions for all configuration items so they can be uniquely referenced and tracked.

  4. A change management process requires that changes with a 'high risk' rating must be approved by the Change Manager AND the CAB. This is an example of which principle?

    Answer: Risk-based approval authority

    Risk-based approval authority assigns higher-level review requirements proportional to the potential impact of a change, ensuring riskier changes receive greater scrutiny.

  5. What is the main risk of NOT having a formal software change control process?

    Answer: Unauthorized or poorly planned changes may destabilize production systems

    Without formal change control, changes may be made without adequate testing, approval, or documentation, leading to system instability, outages, and security vulnerabilities.

  6. Which artifact management practice helps prevent 'dependency confusion' attacks in software builds?

    Answer: Pinning dependencies to specific verified versions and using a private artifact proxy

    Pinning dependencies to specific verified versions and routing through a private artifact proxy prevents attackers from injecting malicious packages via public repositories.