mediummultiple choiceObjective-mapped

An external auditor asks for proof that firewall rule changes were reviewed and approved before being implemented during the last quarter. Which evidence is MOST appropriate to provide?

Question 1mediummultiple choice
Full question →

An external auditor asks for proof that firewall rule changes were reviewed and approved before being implemented during the last quarter. Which evidence is MOST appropriate to provide?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

A screenshot of the firewall management homepage showing that the system is online.

A homepage screenshot does not prove that specific rule changes were reviewed and approved before implementation.

B

Best answer

Change tickets showing requester, reviewer approval, implementation date, and rollback plan.

Change tickets are strong audit evidence because they show who requested the change, who approved it, when it was implemented, and how the organization planned to reverse it if needed. That level of documentation demonstrates governance, traceability, and control over configuration changes, which is exactly what an auditor is trying to verify.

C

Distractor review

An email from the network team stating they remember reviewing the changes.

Memory-based claims are weak evidence because they are not complete, standardized, or reliably traceable for audit purposes.

D

Distractor review

A list of the firewall vendor's product features from the company website.

Vendor features describe product capabilities, not the organization's change approval and review process.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Change tickets showing requester, reviewer approval, implementation date, and rollback plan. — Change tickets are the best evidence because they provide a documented audit trail of the request, approval, implementation, and rollback planning. Auditors want objective proof that control processes were followed, not informal recollections or product descriptions. Well-maintained change records demonstrate that the organization controls firewall modifications and can trace decisions back to specific approvers and dates. Why others are wrong: A screenshot only shows the system exists, not that change governance was followed. An email memory statement is weak, incomplete evidence and is difficult to verify. Vendor feature lists are irrelevant to internal approval workflows. The auditor is asking about process evidence, and change tickets are the most reliable and defensible artifact.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.