CAS-002 · Question #599
The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services. Given the size of…
The correct answer is D. Call an emergency change management meeting to ensure the ACL will not impact core. Before applying a major network ACL change, even during a security incident, the change management process must be followed to assess potential business impact.
Question
The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services. Given the size of the company which deploys over 20,000 workstations and 1,000 servers, the security engineer believes that the best course of action is to block the file sharing service across the organization by placing ACLs on the internal routers. Which of the following should the security administrator do before applying the ACL?
Options
- AQuickly research best practices with respect to stopping Conficker infections and implement
- BConsult with the rest of the security team and get approval on the solution by all the team
- CApply the ACL immediately since this is an emergency that could lead to a widespread data
- DCall an emergency change management meeting to ensure the ACL will not impact core
How the community answered
(40 responses)- A3% (1)
- B8% (3)
- C10% (4)
- D80% (32)
Why each option
Before applying a major network ACL change, even during a security incident, the change management process must be followed to assess potential business impact.
Researching best practices is useful but does not address the need to formally evaluate business impact before making a sweeping infrastructure change.
Getting team consensus is part of change management but does not include the formal impact analysis, approval chain, and rollback plan required before modifying core network infrastructure.
Applying the ACL immediately without review risks blocking legitimate business traffic and causing a self-inflicted outage that may be worse than the infection itself.
Blocking file sharing ports (SMB, TCP 445/139) across 20,000 workstations and 1,000 servers is a high-impact change that could disrupt critical business operations. An emergency change management meeting ensures that stakeholders assess the impact, approve the change, and have a rollback plan in place. Change management safeguards against unintended outages even when the change is security-driven.
Concept tested: Change management before emergency network ACL changes
Source: https://csrc.nist.gov/publications/detail/sp/800-100/final
Topics
Community Discussion
No community discussion yet for this question.