nerdexam
CompTIA

CAS-002 · Question #599

The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services. Given the size of…

The correct answer is D. Call an emergency change management meeting to ensure the ACL will not impact core. Before applying a major network ACL change, even during a security incident, the change management process must be followed to assess potential business impact.

Integration of Computing, Communications and Business Disciplines

Question

The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services. Given the size of the company which deploys over 20,000 workstations and 1,000 servers, the security engineer believes that the best course of action is to block the file sharing service across the organization by placing ACLs on the internal routers. Which of the following should the security administrator do before applying the ACL?

Options

  • AQuickly research best practices with respect to stopping Conficker infections and implement
  • BConsult with the rest of the security team and get approval on the solution by all the team
  • CApply the ACL immediately since this is an emergency that could lead to a widespread data
  • DCall an emergency change management meeting to ensure the ACL will not impact core

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    10% (4)
  • D
    80% (32)

Why each option

Before applying a major network ACL change, even during a security incident, the change management process must be followed to assess potential business impact.

AQuickly research best practices with respect to stopping Conficker infections and implement

Researching best practices is useful but does not address the need to formally evaluate business impact before making a sweeping infrastructure change.

BConsult with the rest of the security team and get approval on the solution by all the team

Getting team consensus is part of change management but does not include the formal impact analysis, approval chain, and rollback plan required before modifying core network infrastructure.

CApply the ACL immediately since this is an emergency that could lead to a widespread data

Applying the ACL immediately without review risks blocking legitimate business traffic and causing a self-inflicted outage that may be worse than the infection itself.

DCall an emergency change management meeting to ensure the ACL will not impact coreCorrect

Blocking file sharing ports (SMB, TCP 445/139) across 20,000 workstations and 1,000 servers is a high-impact change that could disrupt critical business operations. An emergency change management meeting ensures that stakeholders assess the impact, approve the change, and have a rollback plan in place. Change management safeguards against unintended outages even when the change is security-driven.

Concept tested: Change management before emergency network ACL changes

Source: https://csrc.nist.gov/publications/detail/sp/800-100/final

Topics

#change management#incident response#ACL#Conficker

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice