Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A network engineer needs to change an ACL on a production firewall so a new SaaS integration works. The business cannot tolerate an extended outage, and the change must be reversible if testing fails. Which practice best fits?

⚠ Common exam trap

It's easy for candidates to think making changes quickly (Option A) or disabling logging (Option C) is acceptable for a 'simple' ACL change, but the SY0-701 exam emphasizes that any production change must follow formal change management to ensure reversibility and minimize risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Follow formal change management with approval, testing, and rollback planning

Formal change management ensures the ACL modification is documented, tested in a staging environment, and includes a rollback plan (e.g., reverting to a saved configuration or applying a 'no' command for the specific ACL entry). This minimizes downtime by allowing controlled implementation and immediate reversal if the SaaS integration fails, aligning with the business's zero-tolerance for extended outages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Make the change directly during business hours without documentation

    Why it's wrong here

    Directly editing ACLs on a production firewall during peak hours without any change record eliminates the ability to compare pre- and post-change rule sets, making rollback a manual, error-prone reverse-engineering effort. If the SaaS integration misbehaves, there is no governance trail to identify which rule was changed or who approved it, violating the separation of duties and auditability principles required in regulated environments. Furthermore, business-hours implementation needlessly risks a denial of service for all users on the firewall if a syntax error or logic flaw is introduced, whereas a formal window allows for staged testing and immediate remediation.

  • Follow formal change management with approval, testing, and rollback planning

    Why this is correct

    Formal change management ensures that the ACL modification is vetted against security policy, tested in a non-production environment or with a peer review to catch ordering errors or unintended broad access. It provides a documented change window, an escape plan to revert the firewall to a known-good configuration, and post-implementation validation that the SaaS integration works without weakening the firewall posture. This aligns with ITIL and NIST change management practices, ensuring auditability and accountability for a production network change.

  • Disable logging temporarily so the firewall change applies faster

    Why it's wrong here

    Disabling logging on a production firewall during a change removes the very telemetry needed to detect whether the new ACL is misrouting traffic or allowing unauthorized access; the firewall is already processing packets quickly, so logging rarely affects the speed of applying a rule. More importantly, this workaround completely sidesteps the need for change approval and rollback planning, and it introduces a new risk: if the admin forgets to re-enable logging, the security team loses critical audit records for all traffic, potentially violating compliance requirements like PCI DSS or SOC 2. The change itself is still unapproved and untested, so the core failure remains.

  • Ask the vendor to modify the firewall remotely without internal review

    Why it's wrong here

    Allowing a SaaS vendor to directly connect to the production firewall and modify ACLs bypasses the organization's change control processes, meaning no internal validation of the exact rule syntax, source/destination IP ranges, or ports being opened. This creates a supply-chain risk because the vendor's credentials could be compromised, and any misconfiguration becomes an unapproved, undocumented drift that is exceptionally difficult to trace during incident response. Even if the vendor is trusted, remote external changes violate the principle of least privilege and negate the firewall administrator's ability to maintain a controlled baseline and test the change against internal security policies.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.