nerdexam
EC-Council

312-50V10 · Question #807

The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the

The correct answer is D. Immediately roll back the firewall rule until a manager can approve it. Change management procedures should require immediate rollback of any unauthorized firewall rule until proper managerial approval is obtained to preserve policy integrity.

Evading IDS, Firewalls, and Honeypots

Question

The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the firewall configuration, you notice a recently implemented rule but cannot locate manager approval for it. What would be a good step to have in the procedures for a situation like this?

Options

  • AHave the network team document the reason why the rule was implemented without prior
  • BMonitor all traffic using the firewall rule until a manager can approve it.
  • CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager
  • DImmediately roll back the firewall rule until a manager can approve it

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    15% (9)
  • D
    77% (46)

Why each option

Change management procedures should require immediate rollback of any unauthorized firewall rule until proper managerial approval is obtained to preserve policy integrity.

AHave the network team document the reason why the rule was implemented without prior

Documenting the reason after the fact does not remediate the policy violation or remove the potential security risk introduced by the unapproved rule.

BMonitor all traffic using the firewall rule until a manager can approve it.

Monitoring traffic through an unapproved rule allows an unauthorized configuration to remain active, which continues to violate change management policy and may expose the network to additional risk.

CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager

Leaving the rule active on the assumption that the business relies on it circumvents the approval process and rewards bypassing established change controls, creating a precedent for future violations.

DImmediately roll back the firewall rule until a manager can approve itCorrect

Immediately rolling back the unauthorized rule enforces the change management policy and removes a potentially risky configuration that bypassed required approval controls. This action preserves the integrity of the change control process and eliminates any security exposure introduced by the unapproved rule. The rule can be re-implemented correctly once manager approval is granted and the change is properly documented.

Concept tested: Firewall change management and unauthorized rule remediation

Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final

Topics

#firewall rules#change management#security policy#rollback procedures

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice