SY0-701 General Security Concepts Practice Question
An operations manager is worried a single network administrator could quietly push an unauthorized firewall rule. The manager wants every rule change reviewed by a second person and documented before implementation. Which control best addresses this concern?
⚠ Common exam trap
Test-takers frequently confuse detective controls (like logging) or physical controls (like locked racks) with preventive administrative controls, failing to recognize that only a documented approval workflow with two approvers directly enforces the required separation of duties to prevent unauthorized rule changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a documented change-management workflow with two approvers before any firewall rule is applied.
A documented change-management workflow with two approvers directly enforces separation of duties, ensuring that no single administrator can implement a firewall rule change without peer review and documented approval. This control addresses the manager's concern about unauthorized changes by requiring a second person to review and approve before the rule is applied, which is a fundamental principle of access control and change management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable detailed firewall logging so each packet match is written to disk.
Why it's wrong here
Detailed firewall logging is a detective control, not a preventive one. Writing packet-match records to disk creates an audit trail of traffic, but it does not require any approval before the rule is applied or block the change from being made. Additionally, the single administrator could modify logging settings or clear logs after making a hidden change, further weakening this as a safeguard. Thus, logging may help with post-incident investigation but does not reduce the insider risk at the moment the rule is changed.
- ✓
Require a documented change-management workflow with two approvers before any firewall rule is applied.
Why this is correct
Correct. A documented change-management process with dual approval is an administrative control that reduces insider risk and improves accountability. It creates separation of duties, adds review before implementation, and leaves an auditable trail. That combination directly addresses the manager's concern about a single administrator making hidden changes.
- ✗
Move the firewall appliance into a locked equipment rack.
Why it's wrong here
Locking the firewall appliance in a rack addresses physical security, protecting the hardware from theft, tampering, or unauthorized console access. However, firewall rule changes are typically performed over the network via SSH, HTTPS, or a management API, so an administrator needs no physical contact with the device to apply a new rule. This control also introduces no second-person review or approval step, so it does not mitigate the risk of a single administrator making unauthorized configuration changes. Physical security alone cannot enforce separation of duties for logical configuration management.
- ✗
Encrypt the firewall configuration backup with a strong key.
Why it's wrong here
Encrypting the firewall configuration backup protects the confidentiality and integrity of saved configuration files at rest, ensuring that someone who steals the backup cannot read or alter it. This does nothing to the live, running firewall configuration, and it adds no workflow requirement—an administrator can still connect to the appliance and apply a new rule without anyone else reviewing the request. In fact, if the backup is encrypted with a key held by the same administrator, it could even help conceal unauthorized changes by preventing others from inspecting the backup. Therefore, backup encryption is a data-protection control, not a change-governance control.
Go deeper
Related to this question
Learn chapter
Access Control Models (DAC, MAC, RBAC)
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.