Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

An administrator pushed a firewall rule change to allow a new vendor IP range during business hours. Minutes later, payroll users lost access to an internal service. Which change management practice would have best reduced the impact?

⚠ Common exam trap

Many exam-takers think speed of implementation (Option A) is more important than safety, but CompTIA emphasizes that change management processes, including testing and rollback, are critical to prevent production outages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Test the change in a staging environment and include a rollback plan in the request.

Testing the change in a staging environment first would have revealed any unintended side effects, such as ACL conflicts that blocked payroll traffic. Including a rollback plan ensures that if the change causes issues in production, the administrator can quickly revert the firewall rule to restore service. This aligns with the change management process of minimizing impact through controlled testing and contingency planning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply changes directly in production so they take effect as quickly as possible.

    Why it's wrong here

    Directly applying the firewall rule change to production skips the staging validation that could catch misconfigurations, such as unintended deny-all traffic or exposure of a restricted subnet. A faulty rule can immediately disrupt business-critical services or open a security hole, and without a rollback plan the administrator must improvise under pressure. Change management best practice requires testing in a representative environment and having a reversal strategy before touching production.

  • Test the change in a staging environment and include a rollback plan in the request.

    Why this is correct

    This is the best practice because staging validation can reveal unintended access impacts before production is touched. A rollback plan gives operators a fast, documented way to restore service if the change breaks something critical. Together, testing and rollback planning reduce outage duration and support safer operational hardening by making the change controlled, reviewable, and reversible.

  • Avoid documenting the change until after the maintenance window ends.

    Why it's wrong here

    Deferring documentation until after the maintenance window erases the audit trail needed to correlate the firewall rule change with any performance degradation, connectivity loss, or security incident that occurs during that window. If the change causes an outage, responders will have no written record of the exact commands, rule order, or backup state, delaying diagnosis and extending downtime. Documentation is a control that supports troubleshooting, compliance (e.g., PCI-DSS log review), and accountability for every change.

  • Use verbal approval from the payroll manager instead of the normal ticket process.

    Why it's wrong here

    Verbal approval from the payroll manager bypasses the change-request ticket that formally captures scope, risk assessment, technical details, testing results, and the rollback plan. Without a ticket, there is no evidence that the change was authorized, no record for post-incident review, and no mechanism to enforce separation of duties or approval thresholds. This violates change management policy and leaves the organization unable to prove that the firewall modification was reviewed by the appropriate stakeholders.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to add a new vendor IP range to a firewall rule in production. What is the best change-management step to reduce risk?

easy
  • A.Apply the change immediately during peak business hours.
  • B.Test and approve the change before implementing it in production.
  • C.Allow the entire vendor subnet permanently without review.
  • D.Skip documentation to speed up the rollout.

Why B: Change management requires testing and approval before applying changes to production systems. Adding a new vendor IP range to a firewall rule without validation could inadvertently allow malicious traffic or block legitimate traffic, leading to a security breach or service disruption. Testing in a non-production environment or using a change window ensures the rule behaves as intended and aligns with the organization's security policy.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.