Soru

Zorluk: ZorChange Management and Security Impacts

An organization plans to deprecate legacy cryptographic protocols across all internal application gateways during a scheduled maintenance window. Following the change execution, several mission-critical legacy internal applications lose connection to the centralized authentication service, causing widespread business disruption. Investigation reveals that while the protocol deprecation was approved by the Change Advisory Board (CAB), the technical change request did not evaluate application-level dependency on legacy protocol suites. Which of the following change management practices was omitted prior to submission?

  1. Performing a security impact assessment and system dependency analysis to identify technical prerequisites and legacy integration requirements.Cevap
  2. B
    Reclassifying the protocol deprecation from a preventive control to a detective control within the enterprise asset repository.
  3. C
    Deploying network perimeter firewall rules to block port 80 HTTP traffic across affected application segments.
  4. D
    Automating immediate account revocation playbooks within the Security Orchestration, Automation, and Response (SOAR) system.

Cevap

Performing a security impact assessment and system dependency analysis to identify technical prerequisites and legacy integration requirements.
The correct answer emphasizes performing a security impact assessment and dependency analysis. Before any major infrastructure modification is presented to a Change Advisory Board (CAB), administrators must evaluate how security configuration changes affect existing applications and inter-service dependencies. Identifying these legacy requirements ahead of time ensures necessary adjustments or exceptions are addressed before deployment.

Adım Adım Çözüm

1
Analyze the change management failure scenario.
Identified that cryptographic protocol removal caused cascading authentication failures due to unmapped dependencies.
Changes to security settings must be thoroughly evaluated for technical interdependencies before implementation.
2
Evaluate the required pre-implementation change control phase.
A thorough security impact assessment and dependency mapping would have highlighted legacy application reliance on the protocol.
Change management workflows require assessing operational and security impacts to ensure backout plans and compatibility checks are established.

Anahtar Kavram

Security Impact Assessment and Dependency Analysis in Change Management
Bu soruyu puanla