SY0-701 exam dumps

SY0-701 practice question 410 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 410

Single answerProcedures: Change management , Onboarding/offboarding , Playbooks

A company recently terminated a systems administrator and, two days later, discovered that the former employee's VPN account was still active. During the same week, the security team made an emergency firewall change to block suspicious outbound traffic, but the change was not documented and later disrupted a business application. The CISO wants to reduce the risk of both issues happening again while improving consistency during future incidents. Which action would BEST address these concerns?

  1. A

    Implement a formal offboarding checklist tied to HR notifications, require documented approval and rollback steps for emergency changes, and use incident response playbooks for common security events

  2. B

    Allow managers to notify IT informally when employees leave, and let administrators make emergency changes first and document them only if an outage occurs

  3. C

    Require all account changes and firewall updates to be performed only during the monthly maintenance window, regardless of business need or incident severity

  4. D

    Focus on deploying additional endpoint detection agents, since account deprovisioning and firewall documentation are primarily technical issues rather than procedural ones

Show answer and explanation

Correct answer: A

Explanation

The best answer is to strengthen procedures across offboarding, change management, and incident response. In the scenario, the former administrator retained access because offboarding was not reliably triggered or completed. Best practice is to integrate HR, management, and IT workflows so terminations automatically trigger immediate deprovisioning tasks, asset recovery, and access review. For the undocumented firewall change, change management should include approval, testing when feasible, implementation records, and rollback planning. Even emergency changes should be documented after implementation and reviewed to confirm business impact and lessons learned. Playbooks are also important because they provide predefined, repeatable steps for common incidents, helping teams respond quickly and consistently. These practices align with common security governance guidance and operational best practices such as formal account lifecycle management, documented change control processes, and incident response procedures described in frameworks like NIST guidance for security operations and incident handling.

  • A. Correct.

    Correct. This option addresses all three procedural gaps in the scenario. A formal offboarding checklist tied to HR notifications helps ensure timely account deactivation when employees depart. Requiring documented approval, implementation details, and rollback procedures is a core part of sound change management, including emergency changes that still need retrospective documentation and review. Using incident response playbooks improves consistency and speed when handling recurring security events, reducing ad hoc decision-making.

  • B. Incorrect.

    Incorrect. Informal manager notifications are unreliable and commonly lead to delays in deprovisioning, which is exactly what caused the lingering VPN access in the scenario. Similarly, making emergency changes without defined documentation and approval expectations increases operational risk and makes troubleshooting difficult. This choice reflects a weak, ad hoc process rather than mature security procedures.

  • C. Incorrect.

    Incorrect. Restricting all account changes and firewall updates to a monthly maintenance window is impractical and potentially harmful. Offboarding often requires immediate action to reduce insider threat risk, and security incidents may require urgent changes outside normal windows. Good change management supports standard, emergency, and expedited changes with appropriate controls, rather than delaying all actions.

  • D. Incorrect.

    Incorrect. Additional endpoint detection tooling may improve monitoring, but it does not directly solve the procedural failures described. The root causes are gaps in offboarding, change management, and incident handling consistency. Security+ expects candidates to recognize when policy, process, and procedural controls are the most appropriate response rather than defaulting to new technical tools.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam