Which procedure should be followed when setting up new firewall rules?
Which of the following should a security administrator adhere to when setting up a new set of firewall rules?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the principle that any modification to security infrastructure, such as adding firewall rules, is a change and requires a formal change management process to minimize risk and ensure accountability.
When setting up new firewall rules, security administrators must follow change management procedures to ensure changes are controlled and do not disrupt operations. This SY0-701 question is universally answered as Change management, with all community voters selecting option D.
Choosing disaster recovery plan, incident response procedure, or business continuity plan is common because these are security-related plans, but they apply to disruptions and incidents, not to routine system changes like new firewall rules.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Setting up new firewall rules is a modification to the network security infrastructure and thus constitutes a 'change.' Change management procedures provide a structured approach to plan, review, approve, implement, and verify changes, reducing the risk of errors and unauthorized actions. As comment [3] notes, adhering to change management ensures changes are made systematically, reducing errors and enhancing the security posture.
Why the Other Options Are Wrong
Disaster recovery plans (A), incident response procedures (B), and business continuity plans (C) are all designed for reacting to or recovering from adverse events such as outages, security incidents, or disasters. There is no mention of such an event in the question. As comment [5] highlights, these plans are relevant only to an incident or disaster, not to a standard operational change.
Community Comment Notes
All community comments agree on answer D. Comment [1] emphasizes the keyword 'new' firewall rules, indicating that any change must go through change management. Comment [2] warns that improper changes can cause service disruption and stresses submitting a change management request to avoid trouble. Comment [6] simply reaffirms 'D. Change management procedure'. These comments collectively reinforce that change management is the correct and expected answer.
Official Reference
Exam Strategy
Look for keywords in the question: 'new', 'setup', 'change' vs. 'incident', 'disaster'. If the scenario involves modifying infrastructure without any mention of an ongoing incident, always select change management. Remember that firewall rule changes are a classic example of a change management trigger for CompTIA Security+.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →