Question

Difficulty: MediumConfiguration and Change Management

During a routine automated security audit, a network engineer discovers that a custom Access Control List (ACL) rule was manually added directly to a perimeter firewall during an unrecorded late-night troubleshooting session. The rule remains active in production and bypasses the organization's documented security baseline. According to standard change management best practices, which of the following actions should the engineer take first?

  1. A
    Immediately delete the unauthorized ACL rule from the live firewall to restore the exact baseline configuration.
  2. Document the current running configuration, assess operational impact, and submit an emergency Request for Change (RFC) for review.Answer
  3. C
    Manually update the baseline documentation file to include the new ACL rule so that configuration drift tools stop generating alert flags.
  4. D
    Wait for the next scheduled quarterly Change Advisory Board (CAB) meeting to present the issue before documenting the active configuration.

Answer

Document the current running configuration, assess operational impact, and submit an emergency Request for Change (RFC) for review.
When configuration drift (an unapproved manual change) is discovered in production, the correct procedure is to document the active state, analyze business/security impact, and immediately initiate an emergency Request for Change (RFC). This allows the Change Advisory Board (CAB) or emergency change authority to properly authorize either a controlled rollback plan or a permanent baseline modification.

Step-by-Step Solution

1
Identify configuration drift and preserve facts
The unauthorized firewall ACL modification is documented along with its current active state.
Before altering production environments, administrators must fully understand what changes exist and what services might be affected.
2
Initiate emergency change management governance
An emergency RFC is prepared and submitted for formal risk review.
Out-of-band or unrecorded modifications must be processed through emergency change protocols to evaluate security risks and plan a controlled rollback or formal approval.

Key Concept

Configuration Drift Remediation and Emergency RFC Processing
Rate this question