nerdexam
EC-Council

312-50V13 · Question #202

The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing…

The correct answer is D. Immediately roll back the firewall rule until a manager can approve it. Any firewall rule implemented without proper manager approval, violating established security procedures, must be immediately rolled back to maintain security policy integrity.

Submitted by tyler.j· Mar 6, 2026System Hacking

Question

The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the firewall configuration, you notice a recently implemented rule but cannot locate manager approval for it. What would be a good step to have in the procedures for a situation like this?

Options

  • AHave the network team document the reason why the rule was implemented without prior
  • BMonitor all traffic using the firewall rule until a manager can approve it.
  • CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager
  • DImmediately roll back the firewall rule until a manager can approve it

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    11% (4)
  • D
    81% (29)

Why each option

Any firewall rule implemented without proper manager approval, violating established security procedures, must be immediately rolled back to maintain security policy integrity.

AHave the network team document the reason why the rule was implemented without prior

Documenting the reason after the fact does not address the immediate security risk or the procedural violation of implementing the rule without prior approval.

BMonitor all traffic using the firewall rule until a manager can approve it.

Monitoring traffic using an unapproved firewall rule still means the organization is operating under a potentially unauthorized and insecure configuration, which should not be permitted.

CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager

Relying on an unapproved rule for business operations ignores the fundamental security principle of change management and approval, potentially exposing the organization to unknown risks.

DImmediately roll back the firewall rule until a manager can approve itCorrect

Immediately rolling back the firewall rule is the appropriate action because the rule was implemented in direct violation of established security procedures requiring manager approval. Allowing an unapproved rule to persist introduces an unvetted security risk and undermines the control framework.

Concept tested: Change management, security policy enforcement, and incident response for policy violations

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf

Topics

#firewall management#change management#security policy#incident response

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice