Question

Difficulty: HardConfiguration and Change Management

During a routine compliance audit, a network analyst discovers that several perimeter firewalls contain unapproved Access Control List (ACL) rule modifications. Investigation reveals that an on-call administrator applied these inline changes two weeks ago to mitigate an active service disruption, but bypassed standard approval procedures. The temporary fix stabilized traffic but resulted in configuration drift between the active firewall state and the documented network baseline. To resolve this non-compliant state while adhering to formal change management governance, which action should the analyst take first?

  1. Submit a retroactive Request for Change (RFC) including post-implementation risk analysis and baseline documentation for Change Advisory Board (CAB) review.Answer
  2. B
    Immediately restore the firewalls to their pre-outage running configuration files from the previous week's backup repository.
  3. C
    Deploy a differential backup file over the active firewall running configuration to merge baseline settings without taking the devices offline.
  4. D
    Reconfigure the firewall management interfaces to run SNMPv2c community strings to track real-time ACL modification events.

Answer

Submit a retroactive Request for Change (RFC) including post-implementation risk analysis and baseline documentation for Change Advisory Board (CAB) review.
When emergency changes are implemented out-of-band to resolve a critical incident, standard change management governance mandates submitting a retroactive Request for Change (RFC). This process documents the modification, conducts post-implementation risk assessment, updates official baseline documentation, and secures formal Change Advisory Board (CAB) authorization without causing unexpected network downtime.

Step-by-Step Solution

1
Identify the cause of configuration drift and assess operational impact.
Recognized that the running configuration contains necessary emergency operational fixes that deviate from the approved baseline.
Reverting changes immediately could re-trigger a critical service outage.
2
Initiate formal retroactive change management procedures.
Prepare an RFC documenting the incident, the exact delta in configuration, and the justification for bypassing standard pre-approval.
Governance frameworks require emergency changes to be formally documented and reviewed post-incident to align active configurations with official baselines.
3
Submit the RFC to the Change Advisory Board (CAB).
The CAB reviews the operational risks and approves updating the official configuration baseline.
CAB approval ensures organizational visibility, accountability, and compliance alignment.

Key Concept

Configuration Drift Remediation and Retroactive Change Authorization
Estimated Time:2m 0s
Rate this question