712-50 exam dumps

712-50 practice question 296 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 296

Single answerDesign and develop a program to monitor firewalls and identify firewall configuration issues

A global enterprise has grown through acquisitions and now operates dozens of firewalls from multiple vendors across data centers and regional offices. An internal audit found overly permissive rules, undocumented temporary changes, and inconsistent logging settings. The CISO has asked you to design a monitoring program that will continuously identify firewall configuration issues and support governance reporting to senior leadership. Which approach would BEST meet this objective?

  1. A

    Implement a centralized firewall policy management and monitoring process that baselines approved configurations, ingests rule-set and log data from all firewalls, detects policy deviations and risky rules, and ties findings to change management and periodic recertification.

  2. B

    Require each network administrator to review firewall rules quarterly using locally exported spreadsheets and submit attestation emails confirming that rules are still needed.

  3. C

    Increase the firewall log retention period to one year and send all logs to a SIEM, relying on incident analysts to identify configuration issues during investigations.

  4. D

    Schedule annual external penetration tests focused on Internet-facing systems to identify whether firewall misconfigurations can be exploited.

Show answer and explanation

Correct answer: A

Explanation

The best answer is the centralized firewall policy management and monitoring approach because the question asks for a program to continuously identify firewall configuration issues and support governance reporting. In practice, effective firewall monitoring programs include: an approved secure baseline; automated collection and normalization of configurations across vendors; rule analysis for risky patterns such as overly permissive access, unused or shadowed rules, and inconsistent logging; integration with change management to detect unauthorized changes; and periodic access/rule recertification with clear ownership. These practices are consistent with broadly accepted guidance from NIST, especially NIST SP 800-41 on firewalls and firewall policy, as well as NIST guidance on continuous monitoring and configuration management such as NIST SP 800-137 and SP 800-128. From a CCISO perspective, the key is not only deploying tools, but designing a sustainable governance and monitoring program that provides measurable control oversight, accountability, and risk reduction across the enterprise.

  • A. Correct.

    Correct. This is the most effective programmatic approach because it combines governance, technical monitoring, and operational control. A mature firewall monitoring program should include a baseline of approved configurations, centralized collection of policies and logs, automated detection of risky conditions such as overly broad rules, shadowed or unused rules, unauthorized changes, and inconsistent logging, and integration with formal change management. Periodic recertification supports accountability and governance reporting. This aligns with security configuration management, continuous monitoring, and least privilege principles.

  • B. Incorrect.

    Incorrect. Quarterly manual spreadsheet reviews do not scale well in a multi-vendor, multi-region environment and are prone to error, inconsistency, and weak evidence trails. While attestation can be part of governance, by itself it does not provide continuous monitoring, automated detection of policy drift, or strong validation of actual device configurations. It also depends too heavily on administrators self-reporting compliance.

  • C. Incorrect.

    Incorrect. Centralizing logs in a SIEM is valuable, but log retention alone does not adequately identify firewall configuration weaknesses. Many configuration issues, such as redundant rules, excessive network object scope, permissive any-any rules, or undocumented changes, require direct analysis of the rule base and configuration state, not just event logs. Waiting for incident analysts to discover these issues during investigations is reactive rather than preventive.

  • D. Incorrect.

    Incorrect. Penetration testing can help validate external exposure and exploitability, but it is not a substitute for a continuous firewall configuration monitoring program. Annual testing is too infrequent to detect day-to-day rule changes, temporary exceptions that become permanent, or internal segmentation weaknesses. It provides point-in-time assurance rather than ongoing governance and control monitoring.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam