SY0-701 Question 30
Single answerDocumentation: Updating diagrams , Updating policies/proceduresA company recently segmented its network after a ransomware incident. The security administrator moved the finance servers into a new VLAN, added an internal firewall between user and server networks, and changed the approved remote-access process so administrators must use a jump box instead of connecting directly to servers. During a post-incident review, the CISO discovers that several technicians are still following the old process and a new hire used an outdated network map while troubleshooting. Which action should the security team take FIRST to reduce the risk of repeated mistakes?
- A
Update the network and data flow diagrams to reflect the new VLANs, firewall boundaries, and jump box path, and revise the remote-access policy/procedure to match the approved process
- B
Schedule additional firewall rule reviews to confirm the new segmentation is functioning as intended
- C
Require all administrators to reset their passwords and re-enroll in MFA before accessing the environment again
- D
Disable remote administration entirely until the next quarterly security awareness training is completed
Show answer and explanation
Correct answer: A
Explanation
When infrastructure or access methods change after an incident, security teams should promptly update both technical documentation and administrative documentation. In this scenario, two key artifacts are out of date: the network/data flow diagrams and the remote-access policy/procedure. Diagrams should show the new VLAN placement, segmentation points, trust boundaries, and approved access path through the jump box. Policies and procedures should reflect who may use remote access, how it must be performed, and any approval or logging requirements. This follows security best practices for change management and documentation control: implemented security changes must be reflected in current diagrams, standards, runbooks, and procedures so administrators and support staff do not continue using superseded methods. Accurate documentation reduces operational error, improves troubleshooting, supports audits, and helps ensure technical controls are used as designed.
- A. Correct.
Correct. The immediate problem is that personnel are relying on outdated documentation and procedures after a significant environment change. Updating the network diagram and related data flow documentation helps technicians understand the current architecture, including segmentation boundaries and the required jump box path. Revising the remote-access policy and operational procedures ensures administrators follow the approved method. In Security+ terms, accurate documentation supports secure operations, reduces configuration errors, and helps align staff actions with implemented controls.
- B. Incorrect.
Incorrect. Reviewing firewall rules may be useful as a validation step, but it does not address the root cause described in the scenario: staff are using obsolete diagrams and procedures. The segmentation can be technically correct while technicians still make mistakes because the documentation has not been updated.
- C. Incorrect.
Incorrect. Resetting passwords and re-enrolling MFA may improve account security in some cases, but nothing in the scenario indicates compromised credentials or authentication weakness as the primary issue. The problem is process and architecture documentation drift, not identity assurance.
- D. Incorrect.
Incorrect. Disabling remote administration is an overly disruptive response and does not solve the documentation gap. It may even interfere with operations and incident recovery. Quarterly awareness training is also too delayed for a problem that requires immediate correction to technical diagrams and procedures.