Test operating evidence for change approvals

A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CISSP practice

Certification
CISSP
Format
SQL query
Difficulty
hard
Estimated time
35 min
Automated checks
8

The brief

Write one read-only query over changes, approvals and approvers. Return exactly service, total_changes, exceptions, one row per service with production changes implemented from minute 100 inclusive to 200 exclusive. changes has one row per change_id; retain changes with no approval in the denominator. A valid review has the same change_id, a reviewer different from the implementer, and an approvers row for that reviewer AND service where valid_from <= approved_min < valid_until. Normal reviews must be at or before implemented_min; an emergency review may be no later than implemented_min + 15. Earlier authorized reviews are valid for either type. A critical=1 change needs at least two DISTINCT valid reviewers; critical=0 needs one. Count the change as one exception if that quorum is missing. Repeated approvals by one person add no reviewer; extra eligible reviewers do not add tested changes. Unknown, wrong-service and expired reviewers add none. Group by actual service; row order is unrestricted. An empty population returns no rows. Derive the report for new identifiers and repair defects without Reset. These deadlines and quorums are the supplied fictional policy, not universal NIST criteria.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • The worksheet executes one bounded read-only evidence query.
  • The report contains service, total_changes and exceptions in that order.
  • The denominator includes every production change in [100,200), including missing approvals.
  • Count only approvals authorized for the service at approval time.
  • Normal approvals are at or before implementation; emergency approvals are at most 15 minutes after it.
  • The implementer cannot count as an independent reviewer.
  • A critical change needs two distinct eligible reviewers; a normal non-critical change needs one.
  • The report derives each service group from the supplied records, including unfamiliar identifiers and an empty population.

Where this sits in the CISSP blueprint

Domain
Security Assessment and Testing
Objective
Security Control Testing
Skill
Evidence, Coverage and Control Effectiveness

Part of CISSP preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.