Question

Difficulty: MediumChange Management and Security Impacts

An organization is preparing to decommission a legacy Lightweight Directory Access Protocol (LDAP) directory server following a enterprise-wide migration to a cloud identity provider. To ensure business continuity and prevent unexpected service disruptions during the shutdown, which of the following actions should the security team perform FIRST to evaluate the security impact of this change?

  1. Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.Answer
  2. B
    Deploy network firewall access control lists to block port 389 traffic in production immediately to observe which systems fail.
  3. C
    Reclassify the legacy LDAP server as a compensating control within the asset inventory to reduce risk rating prior to removal.
  4. D
    Execute automated orchestrations to purge all user accounts and directory schema attributes without Change Advisory Board review.

Answer

Perform a dependency analysis and review directory authentication logs to identify any remaining applications or devices reliant on the legacy service.
Prior to decommissioning core security or identity infrastructure, change management best practices require conducting a thorough dependency analysis and reviewing system logs. This proactive assessment identifies legacy applications, service accounts, or hardware devices still utilizing the service, allowing administrators to migrate them safely without causing unexpected outages.

Step-by-Step Solution

1
Identify the primary operational and security risk associated with decommissioning critical identity infrastructure.
Undocumented service dependencies could cause critical application outages or fallbacks to insecure authentication methods.
Decommissioning systems requires discovering all integrated components before removing service availability.
2
Evaluate the initial step of a change management security impact assessment.
Reviewing active authentication logs and service configuration references provides empirical evidence of usage.
Empirical log analysis reveals real-time usage patterns that static documentation may omit.
3
Determine the proper sequence prior to change approval and execution.
Performing dependency mapping ensures comprehensive risk mitigation before submitting final change approval requests.
Proactive dependency discovery ensures controlled, risk-aware infrastructure modification.

Key Concept

Dependency mapping and risk analysis in change management workflows
Rate this question