SY0-701 Question 29
Single answerDocumentation: Updating diagrams , Updating policies/proceduresA company recently moved several internal applications from an on-premises server network to a segmented cloud environment and enabled a new VPN path for administrators. During a security review, the incident response team discovered that the network diagram still shows the old server locations and the remote access procedure still instructs administrators to use a retired jump box. Which action should the security administrator take FIRST to best reduce operational and security risk?
- A
Update the network diagrams and remote access procedures through the formal change management/document control process, then communicate the approved changes to administrators and responders
- B
Wait until the next annual policy review cycle so all documentation updates can be completed at the same time
- C
Focus on retraining the incident response team, since the issue was caused by staff relying too heavily on documentation
- D
Remove administrator VPN access until a full penetration test validates the new cloud environment
Show answer and explanation
Correct answer: A
Explanation
This scenario tests documentation maintenance after environmental changes. In Security+ contexts, accurate network diagrams and current policies/procedures are essential security documents because they guide access, incident response, recovery, and administrative actions. When systems are migrated, segmented, or reconfigured, organizations should update architecture diagrams, remote access procedures, and related records through formal change management and document control. Best practice is to version, review, approve, and distribute updated documentation promptly rather than waiting for periodic review cycles. Accurate documentation reduces the chance of misrouting responders, using retired systems, bypassing new controls, or creating unnecessary downtime.
- A. Correct.
Correct. When infrastructure and access methods change, the associated diagrams and procedures must be updated promptly and controlled through formal documentation processes. Accurate diagrams support incident response, troubleshooting, and security analysis, while current procedures prevent administrators from following obsolete steps that could cause outages or security gaps. Communicating the approved updates ensures the revised documentation is actually used.
- B. Incorrect.
Incorrect. Deferring updates until an annual review leaves teams using inaccurate documentation for an extended period. In practice, documentation tied to architecture and operational procedures should be updated whenever significant changes occur, especially when those changes affect access paths, segmentation, or response activities.
- C. Incorrect.
Incorrect. Training is important, but the underlying problem is stale documentation after an environmental change. Staff are expected to rely on approved diagrams and procedures during incidents and maintenance. Blaming users instead of correcting source documentation does not address the root cause.
- D. Incorrect.
Incorrect. Temporarily removing VPN access may reduce one potential exposure, but it does not directly solve the identified documentation problem and could disrupt legitimate administration. A penetration test may be valuable later, but the first priority is to align diagrams and procedures with the current environment so teams can operate safely and correctly.