SY0-701 Security Operations Practice Question
An administrator pushed a firewall rule change to allow a new vendor IP range during business hours. Minutes later, payroll users lost access to an internal service. Which change management practice would have best reduced the impact?
⚠ Common exam trap
Many exam-takers think speed of implementation (Option A) is more important than safety, but CompTIA emphasizes that change management processes, including testing and rollback, are critical to prevent production outages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test the change in a staging environment and include a rollback plan in the request.
Testing the change in a staging environment first would have revealed any unintended side effects, such as ACL conflicts that blocked payroll traffic. Including a rollback plan ensures that if the change causes issues in production, the administrator can quickly revert the firewall rule to restore service. This aligns with the change management process of minimizing impact through controlled testing and contingency planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply changes directly in production so they take effect as quickly as possible.
Why it's wrong here
Directly applying the firewall rule change to production skips the staging validation that could catch misconfigurations, such as unintended deny-all traffic or exposure of a restricted subnet. A faulty rule can immediately disrupt business-critical services or open a security hole, and without a rollback plan the administrator must improvise under pressure. Change management best practice requires testing in a representative environment and having a reversal strategy before touching production.
- ✓
Test the change in a staging environment and include a rollback plan in the request.
Why this is correct
This is the best practice because staging validation can reveal unintended access impacts before production is touched. A rollback plan gives operators a fast, documented way to restore service if the change breaks something critical. Together, testing and rollback planning reduce outage duration and support safer operational hardening by making the change controlled, reviewable, and reversible.
- ✗
Avoid documenting the change until after the maintenance window ends.
Why it's wrong here
Deferring documentation until after the maintenance window erases the audit trail needed to correlate the firewall rule change with any performance degradation, connectivity loss, or security incident that occurs during that window. If the change causes an outage, responders will have no written record of the exact commands, rule order, or backup state, delaying diagnosis and extending downtime. Documentation is a control that supports troubleshooting, compliance (e.g., PCI-DSS log review), and accountability for every change.
- ✗
Use verbal approval from the payroll manager instead of the normal ticket process.
Why it's wrong here
Verbal approval from the payroll manager bypasses the change-request ticket that formally captures scope, risk assessment, technical details, testing results, and the rollback plan. Without a ticket, there is no evidence that the change was authorized, no record for post-incident review, and no mechanism to enforce separation of duties or approval thresholds. This violates change management policy and leaves the organization unable to prove that the firewall modification was reviewed by the appropriate stakeholders.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Access Control List
An Access Control List is a set of rules that decides which traffic is allowed or denied entry to a network or device.
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to add a new vendor IP range to a firewall rule in production. What is the best change-management step to reduce risk?
easy- A.Apply the change immediately during peak business hours.
- ✓ B.Test and approve the change before implementing it in production.
- C.Allow the entire vendor subnet permanently without review.
- D.Skip documentation to speed up the rollout.
Why B: Change management requires testing and approval before applying changes to production systems. Adding a new vendor IP range to a firewall rule without validation could inadvertently allow malicious traffic or block legitimate traffic, leading to a security breach or service disruption. Testing in a non-production environment or using a change window ensures the rule behaves as intended and aligns with the organization's security policy.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.