Which Remediation Reduces Risk from Outdated Firewall Configurations?

During a routine penetration test of a customer’s physical data center, a penetration tester observes that no changes have been made to the production firewalls in more than five years. Which of the following is the most appropriate remediation technique to reduce the risk of future security breaches?

  1. Video surveillance
  2. Biometric controls
  3. Password encryption
  4. SSH key rotation Source Reference Answer

Community Votes

D
75%
B
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to identify the logical/technical control directly related to the outdated firewall configuration, while the phrase 'physical data center' is a distractor that leads many to choose a physical security control.

This PenTest+ question asks for the most appropriate remediation when production firewalls have been unchanged for over five years. The community consensus favors SSH key rotation (D) as a technical control that secures administrative access, despite ambiguity from the phrase 'physical data center.'

Choosing B (Biometric controls) because of the mention of 'physical data center' – but the vulnerability is stale firewall configuration, not physical access. Biometrics protect physical entry points, not firewall administrative credentials or keys.

Community Discussion (6 comments)

kinny4000 👍 1 Selected: D
What a dumb question again, CompTIA want us to be confused about whether or not this is a physical pentest by saying "routine pentest of a physical data centre". Wtf does that mean? Is it a physical pentest? If so, then the answer is biometric control, and the 5 year old firewall configuration is there to confuse you. If it's not a physical pentest then the answer is SSH key rotation and the word "physical" is there to confuse you. Either way you're confused
Learner213 👍 2 Selected: D
D is the test question answer but, they are implementing a technical/logical control and referring, in the questions, to a "Physical" assessment. WACK
Etc_Shadow28000 👍 1 Selected: D
To reduce the risk of future security breaches related to outdated firewall configurations D. SSH key rotation: Regularly rotating SSH keys is a good practice for maintaining secure access to systems, including firewalls. However, the primary concern here seems to be the lack of updates to the firewall rules and configurations. Therefore, more broadly, this issue highlights the need for regular reviews and updates of firewall rules and configurations to ensure they are aligned with current security best practices and threats. A. Video surveillance: While important for physical security, it does not directly address the issue of outdated firewall configurations. B. Biometric controls: This also pertains to physical security and access control rather than network security or firewall management. C. Password encryption: While critical for protecting credentials, it does not directly affect firewall configuration management or updates.
Paula77 👍 1 Selected: D
The only answer that addresses outdated firewall configurations
Sebatian20 👍 2 Selected: B
Trick question - "physical data center" I believe the mentioning of the firewall is irrelevant as they are talking about physical security. Thus, B is the correct answer.
041ba31 👍 1 Selected: D
SSH key rotation involves regularly changing SSH keys to ensure secure access controls are maintained. This practice can help secure the management of firewalls, especially if they haven't been updated or changed in a long time, by preventing unauthorized access due to compromised or outdated keys

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

SSH key rotation (D) is the only option that directly mitigates the risk of unauthorized access to firewall management interfaces. Since the firewall configuration has not changed in five years, it is highly likely that administrative SSH keys are also stale or compromised, making rotation the best remediation. The question is framed as a routine penetration test, and the tester's observation points to a technical/logical control deficiency, not a physical one.

Why the Other Options Are Wrong

A (Video surveillance) addresses physical monitoring, not firewall configuration management. B (Biometric controls) is a physical access control, which is irrelevant to the outdated firewall rules described. C (Password encryption) is a secure storage practice, but the question specifically mentions that no changes were made to the firewalls – the issue is credential/access hygiene, and SSH key rotation is more actionable that simply encrypting passwords. Only D provides a direct remediation for maintaining secure, current administrative access to the firewalls.

Community Comment Notes

Several commenters (likes=2) incorrectly argued for B due to the 'physical data center' phrase, calling it a 'trick question.' However, others (likes=1) correctly pointed out that the firewall is a technical component, and the five-year unchanged state indicates a need for rotating SSH keys or similar access controls. One commenter (likes=1) explicitly stated 'The only answer that addresses outdated firewall configurations,' reinforcing D. The debate illustrates a common trap: overthinking the 'physical' prefix instead of following the logical trail of the firewall's age and management access.

Official Reference

Exam Strategy

When a question mentions a 'physical data center' followed by a technical detail like firewall configuration, focus on the component that is outdated or risky. Ask yourself: 'What control would directly address this specific observation?' Here, SSH key rotation is the only option that secures the firewall's administrative channel, so ignore the physical security distractors and pick the technical remediation.

Related Analysis

← Back to PT0-002 Study Guide