mediummultiple choiceObjective-mapped

A network engineer needs to change an ACL on a production firewall so a new SaaS integration works. The business cannot tolerate an extended outage, and the change must be reversible if testing fails. Which practice best fits?

Question 1mediummultiple choice
Full question →

A network engineer needs to change an ACL on a production firewall so a new SaaS integration works. The business cannot tolerate an extended outage, and the change must be reversible if testing fails. Which practice best fits?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Make the change directly during business hours without documentation

Undocumented changes increase outage risk and make rollback and accountability much harder.

B

Best answer

Follow formal change management with approval, testing, and rollback planning

Change management provides traceability, validation, and a prepared rollback path for production changes.

C

Distractor review

Disable logging temporarily so the firewall change applies faster

Disabling logging reduces visibility and does not address approval, testing, or recovery needs.

D

Distractor review

Ask the vendor to modify the firewall remotely without internal review

External execution without internal control weakens oversight and can create unauthorized configuration drift.

Common exam trap

Common exam trap: ACLs stop at the first match

ACLs are processed top to bottom. The first matching entry wins, and an implicit deny usually exists at the end.

Technical deep dive

How to think about this question

ACL questions test precision: source, destination, protocol, port and direction. A generally correct ACL can still fail if it is applied on the wrong interface or in the wrong direction.

KKey Concepts to Remember

  • Standard ACLs match source addresses.
  • Extended ACLs can match source, destination, protocol and ports.
  • The first matching ACL entry is used.
  • There is usually an implicit deny at the end.

TExam Day Tips

  • Check inbound versus outbound direction.
  • Read the ACL from top to bottom.
  • Look for a broader permit or deny above the intended line.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Standard ACLs match source addresses.

What is the correct answer to this question?

The correct answer is: Follow formal change management with approval, testing, and rollback planning — Formal change management is the best choice because it balances business need with control and reversibility. A production firewall ACL can affect availability and security, so the organization needs approval, testing, documented implementation steps, and a rollback plan. That process reduces the chance of unexpected outage while preserving accountability and auditability. It also supports emergency handling if the change needs to be backed out quickly. Why others are wrong: Making the change informally creates unnecessary outage and audit risk. Disabling logging sacrifices visibility and does not solve process control requirements. Allowing the vendor to act without internal review weakens governance and can introduce unauthorized or poorly understood changes.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.