During a routine automated security audit, a network engineer discovers that a custom Access Control List (ACL) rule was manually added directly to a perimeter firewall during an unrecorded late-night troubleshooting session. The rule remains active in production and bypasses the organization's documented security baseline. According to standard change management best practices, which of the following actions should the engineer take first?
- AImmediately delete the unauthorized ACL rule from the live firewall to restore the exact baseline configuration.
- Document the current running configuration, assess operational impact, and submit an emergency Request for Change (RFC) for review.Cevap
- CManually update the baseline documentation file to include the new ACL rule so that configuration drift tools stop generating alert flags.
- DWait for the next scheduled quarterly Change Advisory Board (CAB) meeting to present the issue before documenting the active configuration.
Cevap
Document the current running configuration, assess operational impact, and submit an emergency Request for Change (RFC) for review.
When configuration drift (an unapproved manual change) is discovered in production, the correct procedure is to document the active state, analyze business/security impact, and immediately initiate an emergency Request for Change (RFC). This allows the Change Advisory Board (CAB) or emergency change authority to properly authorize either a controlled rollback plan or a permanent baseline modification.
Adım Adım Çözüm
Anahtar Kavram
Configuration Drift Remediation and Emergency RFC Processing