712-50 exam dumps

712-50 practice question 297 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 297

Single answerDesign and develop a program to monitor firewalls and identify firewall configuration issues

A global enterprise has acquired three regional companies, each using different firewall vendors and rule management practices. During a recent internal audit, the security team found several high-risk issues: overly permissive any-any rules, expired temporary access rules that were never removed, and undocumented policy changes made directly on devices. The CISO wants to design a monitoring program that will continuously identify firewall configuration issues across all environments and provide defensible reporting to executive leadership and auditors. Which approach would BEST meet this objective?

  1. A

    Implement a centralized firewall policy monitoring and compliance process that ingests configurations from all firewall platforms, baselines approved rules, detects drift from approved configurations, identifies risky rules and stale objects, correlates changes to formal change records, and reports remediation metrics over time.

  2. B

    Require firewall administrators to export rule sets to spreadsheets every quarter and have internal audit manually compare them against network diagrams and prior reports.

  3. C

    Increase firewall logging levels for allowed and denied traffic on all devices and use those logs as the primary method to identify configuration weaknesses and unauthorized rule changes.

  4. D

    Schedule annual penetration tests focused on segmentation boundaries and use the findings as the main mechanism to validate firewall rule quality and configuration compliance.

Show answer and explanation

Correct answer: A

Explanation

The best answer is the centralized policy monitoring and compliance approach because the question asks for a program to continuously monitor firewalls and identify configuration issues in a complex, multi-vendor environment. Effective firewall monitoring at the executive level should combine technical control assessment with governance mechanisms: configuration baselining, rule recertification, risk scoring, change reconciliation, exception tracking, and trend reporting. Industry best practices from security configuration management and change management emphasize maintaining secure baselines, detecting unauthorized changes, and continuously assessing compliance. Relevant guidance includes NIST SP 800-41 on firewalls and firewall policy, NIST SP 800-53 controls such as CM-2 (baseline configuration), CM-3 (configuration change control), CM-6 (configuration settings), and CA-7 (continuous monitoring), as well as CIS Controls relating to secure configuration and audit log management. In practice, the strongest program uses centralized collection of firewall configurations, automated analysis for risky constructs, integration with change records, and governance reporting that shows reduction of exposure over time.

  • A. Correct.

    Correct. This is the most effective programmatic approach because it supports continuous monitoring across multiple vendors, compares actual configurations to an approved baseline, detects unauthorized or undocumented changes, and identifies common configuration issues such as overly broad rules, unused objects, shadowed rules, stale temporary rules, and policy drift. It also ties technical findings to governance by reconciling changes with the formal change management process and producing measurable trends for leadership and audit. This aligns with security configuration management, continuous control monitoring, and change-control best practices.

  • B. Incorrect.

    Incorrect. Quarterly spreadsheet reviews are too manual, too infrequent, and highly error-prone for a multi-vendor enterprise environment. This approach may satisfy a minimal review requirement but does not provide continuous monitoring, timely detection of risky changes, or scalable evidence for auditors. A candidate might choose this because manual review has historically been common, but it is not the best design for an enterprise monitoring program.

  • C. Incorrect.

    Incorrect. Traffic logs are useful for operational monitoring, threat detection, and troubleshooting, but they are not sufficient as the primary mechanism for detecting configuration weaknesses or unauthorized rule changes. Logs may show what traffic was allowed or denied, but they do not reliably identify policy intent, rule recertification status, stale exceptions, or whether a direct configuration change bypassed the approval workflow. This option confuses event monitoring with configuration governance.

  • D. Incorrect.

    Incorrect. Penetration testing is valuable for validating security outcomes and identifying exploitable segmentation weaknesses, but it is periodic and sample-based. It does not provide continuous visibility into configuration drift, expired rules, or undocumented changes. Someone might choose this because pen tests can reveal serious firewall issues, but they are a validation activity, not the core of a monitoring program.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam