Test operating evidence for change approvals
A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
Try this labAll CISSP practice
- Certification
- CISSP
- Format
- SQL query
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 8
The brief
Write one read-only query over changes, approvals and approvers. Return exactly service, total_changes, exceptions, one row per service with production changes implemented from minute 100 inclusive to 200 exclusive. changes has one row per change_id; retain changes with no approval in the denominator. A valid review has the same change_id, a reviewer different from the implementer, and an approvers row for that reviewer AND service where valid_from <= approved_min < valid_until. Normal reviews must be at or before implemented_min; an emergency review may be no later than implemented_min + 15. Earlier authorized reviews are valid for either type. A critical=1 change needs at least two DISTINCT valid reviewers; critical=0 needs one. Count the change as one exception if that quorum is missing. Repeated approvals by one person add no reviewer; extra eligible reviewers do not add tested changes. Unknown, wrong-service and expired reviewers add none. Group by actual service; row order is unrestricted. An empty population returns no rows. Derive the report for new identifiers and repair defects without Reset. These deadlines and quorums are the supplied fictional policy, not universal NIST criteria.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- The worksheet executes one bounded read-only evidence query.
- The report contains service, total_changes and exceptions in that order.
- The denominator includes every production change in [100,200), including missing approvals.
- Count only approvals authorized for the service at approval time.
- Normal approvals are at or before implementation; emergency approvals are at most 15 minutes after it.
- The implementer cannot count as an independent reviewer.
- A critical change needs two distinct eligible reviewers; a normal non-critical change needs one.
- The report derives each service group from the supplied records, including unfamiliar identifiers and an empty population.
Where this sits in the CISSP blueprint
- Domain
- Security Assessment and Testing
- Objective
- Security Control Testing
- Skill
- Evidence, Coverage and Control Effectiveness
Part of CISSP preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.