SY0-701 exam dumps

SY0-701 practice question 23 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 23

Single answer1.3 Explain the importance of change management processes and the impact to security.

A company experienced a two-hour outage after a network engineer changed firewall rules during business hours to quickly restore access for a vendor. The change accidentally exposed an internal management interface to the internet, and the security team later discovered repeated login attempts against that interface. Leadership wants to reduce the likelihood and security impact of similar incidents without preventing urgent fixes. Which action would BEST improve the organization's change management process?

  1. A

    Require all firewall changes to be implemented immediately by any available administrator to minimize downtime

  2. B

    Implement a formal change process that includes risk and security impact analysis, testing/approval, scheduled maintenance windows when possible, and documented rollback procedures for emergency and standard changes

  3. C

    Allow engineers to make emergency changes without documentation as long as they inform the security team after the change is complete

  4. D

    Block all vendor-related firewall rule changes unless they are reviewed during the next annual security assessment

Show answer and explanation

Correct answer: B

Explanation

The best answer is to implement a formal change management process that balances availability with security. In this scenario, the organization suffered both an outage and a security exposure because a firewall change was made quickly without sufficient review or safeguards. Effective change management helps prevent misconfigurations by requiring security impact analysis, documented approvals, testing, implementation planning, maintenance windows where appropriate, and rollback procedures. It should also define an emergency change process so urgent fixes can be made quickly but still include minimal authorization, logging, and post-implementation review. These practices align with common security and governance guidance such as NIST SP 800-128 for security-focused configuration management and broadly accepted IT service management change control practices. From a Security+ perspective, the key concept is that unmanaged or poorly managed changes can directly create outages, weaken security controls, expand attack surfaces, and complicate auditing and incident response.

  • A. Incorrect.

    This is incorrect because speed alone does not improve security or reliability. Allowing any available administrator to make immediate firewall changes increases the chance of configuration errors, unauthorized changes, lack of accountability, and unreviewed security exposure. Change management is intended to reduce these risks through authorization, validation, and traceability.

  • B. Correct.

    This is correct because it addresses both operational needs and security controls. A strong change management process should include evaluating the security impact of proposed changes, obtaining appropriate approval, testing before implementation, using maintenance windows when feasible to reduce business impact, and maintaining rollback plans in case the change causes outages or introduces risk. Mature processes also include emergency change paths so urgent fixes can still occur, but with expedited approval and post-change review.

  • C. Incorrect.

    This is incorrect because emergency changes still need to be controlled. While organizations often allow expedited handling for emergencies, skipping documentation creates gaps in accountability, auditability, and incident response. Without records of what changed, when it changed, and who approved it, the organization cannot reliably investigate problems or prove compliance.

  • D. Incorrect.

    This is incorrect because it is overly restrictive and does not support business operations. Vendor connectivity changes may be legitimate and time-sensitive. Deferring all such changes until an annual assessment would harm availability and business responsiveness. The issue is not that vendor-related changes exist; it is that changes must be assessed, approved, tested, and documented appropriately.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam