Which procedure should be followed when setting up new firewall rules?

Which of the following should a security administrator adhere to when setting up a new set of firewall rules?

  1. Disaster recovery plan
  2. Incident response procedure
  3. Business continuity plan
  4. Change management procedure Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the principle that any modification to security infrastructure, such as adding firewall rules, is a change and requires a formal change management process to minimize risk and ensure accountability.

When setting up new firewall rules, security administrators must follow change management procedures to ensure changes are controlled and do not disrupt operations. This SY0-701 question is universally answered as Change management, with all community voters selecting option D.

Choosing disaster recovery plan, incident response procedure, or business continuity plan is common because these are security-related plans, but they apply to disruptions and incidents, not to routine system changes like new firewall rules.

Community Discussion (6 comments)

CyberPark17 👍 19 Selected: D
The keyword is "new" firewall rules. Any change must be adhered to change management procedures.
MAKOhunter33333333 👍 11 Selected: D
Want to make sure the new WF rules do not interfere or cause disruption in service and network, submit a change management request or else you be in big doo doo
9149f41 👍 1 Selected: D
Disaster recovery, incident response, and business continuity plans are relevant to an incident or disaster, but in the question, there is no such incident or disaster mentioned. A change in the system could be done for many reasons, like updating, adding, or deleting any rule.
gollum9 👍 1 Selected: D
D. Change management procedure
dbrowndiver 👍 6 Selected: D
Implementing new firewall rules is a significant change to the network security infrastructure. Adhering to change management procedures ensures these changes are made systematically, reducing the risk of errors and enhancing the security posture.
An381038 👍 6 Selected: D
D. Change management procedure

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Setting up new firewall rules is a modification to the network security infrastructure and thus constitutes a 'change.' Change management procedures provide a structured approach to plan, review, approve, implement, and verify changes, reducing the risk of errors and unauthorized actions. As comment [3] notes, adhering to change management ensures changes are made systematically, reducing errors and enhancing the security posture.

Why the Other Options Are Wrong

Disaster recovery plans (A), incident response procedures (B), and business continuity plans (C) are all designed for reacting to or recovering from adverse events such as outages, security incidents, or disasters. There is no mention of such an event in the question. As comment [5] highlights, these plans are relevant only to an incident or disaster, not to a standard operational change.

Community Comment Notes

All community comments agree on answer D. Comment [1] emphasizes the keyword 'new' firewall rules, indicating that any change must go through change management. Comment [2] warns that improper changes can cause service disruption and stresses submitting a change management request to avoid trouble. Comment [6] simply reaffirms 'D. Change management procedure'. These comments collectively reinforce that change management is the correct and expected answer.

Official Reference

Exam Strategy

Look for keywords in the question: 'new', 'setup', 'change' vs. 'incident', 'disaster'. If the scenario involves modifying infrastructure without any mention of an ongoing incident, always select change management. Remember that firewall rule changes are a classic example of a change management trigger for CompTIA Security+.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide