exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 49 discussion

Actual exam question from CompTIA's SY0-701
Question #: 49
Topic #: 1
[All SY0-701 Questions]

While troubleshooting a firewall configuration, a technician determines that a “deny any” policy should be added to the bottom of the ACL. The technician updates the policy, but the new policy causes several company servers to become unreachable.
Which of the following actions would prevent this issue?

  • A. Documenting the new policy in a change request and submitting the request to change management
  • B. Testing the policy in a non-production environment before enabling the policy in the production network
  • C. Disabling any intrusion prevention signatures on the “deny any” policy prior to enabling the new policy
  • D. Including an “allow any” policy above the “deny any” policy
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SHADTECH123
Highly Voted 8 months ago
Selected Answer: B
Testing the policy in a non-production environment allows for the identification and resolution of any unforeseen issues, such as servers becoming unreachable, before implementing the policy in the production network. This ensures that any potential impact on business operations is minimized.
upvoted 10 times
...
Examplary
Highly Voted 3 months, 1 week ago
Frankly it should be both A and B. Submitting it to change management does not prevent the issue if it isn't caught by change management, and testing it in non-prod would but also shouldn't be done without a request to change management. It's a different question than the previous one regarding change management: Yes the technician SHOULD put in a change management request first, but that's not the question, the question is what would prevent it and the change management request does not prevent an issue, rather it lets everyone know what is happening and provides a backout plan if issues come up. That still does not PREVENT the issue though so /shrug
upvoted 8 times
...
darpanne
Most Recent 3 weeks, 4 days ago
Selected Answer: B
Testing the policy in a non-production environment allows the technician to identify and fix any unintended consequences before implementing the rule in the production network. This ensures the servers and critical services remain reachable while maintaining security.
upvoted 1 times
...
MaxiPrince
1 month ago
Selected Answer: B
. Testing the policy in a non-production environment before enabling the policy in the production network
upvoted 1 times
...
MaxiPrince
1 month, 1 week ago
Selected Answer: B
Test policy in no prod environment
upvoted 1 times
...
43a41d4
1 month, 2 weeks ago
Selected Answer: B
Since the question mentions that the technician has already updates the policy, we can assume that he got approval first to implement the solution. But, for a good technician to perform well and avoid any issues, he should test the changes in a non-production environment. Both questions A and B are good answers, but B est is the best one in this case.
upvoted 1 times
...
3dk1
2 months ago
Selected Answer: A
B is something that should have been done. HOWEVER, if we documented the new change and submitted a change request this issue could have been prevented as well.
upvoted 1 times
...
Bito808
2 months, 3 weeks ago
Selected Answer: A
The answer is "A"! You will get fired if you did not put in a change request before testing or implementing anything! It needs to be documented and approved FIRST! This will determine if you need equipment, resources, special access, or if there's even budget!
upvoted 2 times
...
Bito808
2 months, 3 weeks ago
The answer is "A"! You will get fired if you did not put in a change request before testing or implementing anything! It needs to be documented and approved FIRST! This will determine if you need equipment, resources, special access, or if there's even budget!
upvoted 1 times
...
User92
3 months, 1 week ago
Selected Answer: A
Should be A, check Question #30
upvoted 1 times
...
User92
3 months, 1 week ago
Selected Answer: A
Change Management Processes: Schedule maintenance windows, Thorough backout plans, Consistent “testing” post-implementation
upvoted 2 times
...
Gigz_77
3 months, 2 weeks ago
Selected Answer: A
A. Documenting the new policy in a change request and submitting the request to change management
upvoted 1 times
...
linuxer
3 months, 3 weeks ago
Selected Answer: A
change management request will include testing the updated policy before implementing it
upvoted 1 times
...
Twphill
4 months ago
Answer A: Before any changes are made, the request should be submitted to Change Management. As part of Change Management, the change will be tested in a non-production environment. This is not the responsibility of the technician that decided to make the change. His job is to request the change.
upvoted 2 times
...
tamdod
4 months, 2 weeks ago
Shouldn't a change management be submitted before changing the firewall? That way other people have a change to look at it, and more than likely someone would have caught the problem before it occurred.
upvoted 4 times
...
TrebleSmith
5 months ago
D would work in a chaotic way lol
upvoted 1 times
...
dbrowndiver
5 months, 1 week ago
Selected Answer: B
By testing the policy in a non-production environment, the technician can identify potential issues, such as legitimate traffic being blocked, before applying the changes to the production network. This approach allows for adjustments and troubleshooting in a safe setting, minimizing the risk of disruption to business operations.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago