312-50V13 · Question #202
The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing…
The correct answer is D. Immediately roll back the firewall rule until a manager can approve it. Any firewall rule implemented without proper manager approval, violating established security procedures, must be immediately rolled back to maintain security policy integrity.
Question
Options
- AHave the network team document the reason why the rule was implemented without prior
- BMonitor all traffic using the firewall rule until a manager can approve it.
- CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager
- DImmediately roll back the firewall rule until a manager can approve it
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- C11% (4)
- D81% (29)
Why each option
Any firewall rule implemented without proper manager approval, violating established security procedures, must be immediately rolled back to maintain security policy integrity.
Documenting the reason after the fact does not address the immediate security risk or the procedural violation of implementing the rule without prior approval.
Monitoring traffic using an unapproved firewall rule still means the organization is operating under a potentially unauthorized and insecure configuration, which should not be permitted.
Relying on an unapproved rule for business operations ignores the fundamental security principle of change management and approval, potentially exposing the organization to unknown risks.
Immediately rolling back the firewall rule is the appropriate action because the rule was implemented in direct violation of established security procedures requiring manager approval. Allowing an unapproved rule to persist introduces an unvetted security risk and undermines the control framework.
Concept tested: Change management, security policy enforcement, and incident response for policy violations
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf
Topics
Community Discussion
No community discussion yet for this question.