During a routine compliance audit, a network analyst discovers that several perimeter firewalls contain unapproved Access Control List (ACL) rule modifications. Investigation reveals that an on-call administrator applied these inline changes two weeks ago to mitigate an active service disruption, but bypassed standard approval procedures. The temporary fix stabilized traffic but resulted in configuration drift between the active firewall state and the documented network baseline. To resolve this non-compliant state while adhering to formal change management governance, which action should the analyst take first?
- Submit a retroactive Request for Change (RFC) including post-implementation risk analysis and baseline documentation for Change Advisory Board (CAB) review.Answer
- BImmediately restore the firewalls to their pre-outage running configuration files from the previous week's backup repository.
- CDeploy a differential backup file over the active firewall running configuration to merge baseline settings without taking the devices offline.
- DReconfigure the firewall management interfaces to run SNMPv2c community strings to track real-time ACL modification events.
Answer
Submit a retroactive Request for Change (RFC) including post-implementation risk analysis and baseline documentation for Change Advisory Board (CAB) review.
When emergency changes are implemented out-of-band to resolve a critical incident, standard change management governance mandates submitting a retroactive Request for Change (RFC). This process documents the modification, conducts post-implementation risk assessment, updates official baseline documentation, and secures formal Change Advisory Board (CAB) authorization without causing unexpected network downtime.
Step-by-Step Solution
Key Concept
Configuration Drift Remediation and Retroactive Change Authorization
Estimated Time:2m 0s