312-50V11 · Question #807
The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the
The correct answer is D. Immediately roll back the firewall rule until a manager can approve it. When an unauthorized firewall rule is discovered that bypasses the required change approval process, the correct response is immediate rollback to restore a known-good, approved state.
Question
The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the firewall configuration, you notice a recently implemented rule but cannot locate manager approval for it. What would be a good step to have in the procedures for a situation like this?
Options
- AHave the network team document the reason why the rule was implemented without prior
- BMonitor all traffic using the firewall rule until a manager can approve it.
- CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager
- DImmediately roll back the firewall rule until a manager can approve it
How the community answered
(36 responses)- A3% (1)
- B8% (3)
- C6% (2)
- D83% (30)
Why each option
When an unauthorized firewall rule is discovered that bypasses the required change approval process, the correct response is immediate rollback to restore a known-good, approved state.
Documenting the reason after the fact does not remediate the policy violation or eliminate the security risk posed by an unvetted firewall rule.
Monitoring traffic through an unapproved rule does not address the change control violation and leaves an unauthorized network path active indefinitely.
Leaving an unauthorized rule in place - even temporarily - violates the change management policy and could expose the network to harm while waiting for retroactive approval.
Immediately rolling back the unapproved rule enforces the change management policy and removes a potentially malicious or misconfigured rule that could introduce security vulnerabilities. The rule can be re-implemented once it goes through the proper approval workflow, ensuring accountability and auditability.
Concept tested: Firewall change management and unauthorized rule remediation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-41r1.pdf
Topics
Community Discussion
No community discussion yet for this question.