exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 616 discussion

Actual exam question from CompTIA's SY0-601
Question #: 616
Topic #: 1
[All SY0-601 Questions]

While troubleshooting a firewall configuration, a technician determines that a "deny any" policy should be added to the bottom of the ACL. The technician updates the policy, but the new policy causes several company servers to become unreachable. Which of the following actions would prevent this issue?

  • A. Documenting the new policy in a change request and submitting the request to change management
  • B. Testing the policy in a non-production environment before enabling the policy in the production network
  • C. Disabling any intrusion prevention signatures on the "deny any" policy prior to enabling the new policy
  • D. Including an “allow any" policy above the "deny any" policy
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DChilds
Highly Voted 1 year, 9 months ago
Selected Answer: A
At first I thought B but I realize how impractical that would be in the real world. Unlike applications, you cannot deploy firewall policies in a test environment as the rules are declarative (you know something is getting blocked even if you don't know what exactly that will be). So, I'd go with A because the Change Advisory Board needs to go through the request, gauge the risks, rollback actions and points etc.
upvoted 15 times
...
Jacksoms
Highly Voted 1 year, 8 months ago
Just when I thought we have started getting correct answers from examtopics lol
upvoted 10 times
...
cf6159f
Most Recent 1 year ago
Selected Answer: A
Change it to fix it
upvoted 1 times
...
jkalfo
1 year, 1 month ago
this is a dumba** question . how is submitting a change request going to prevent the issue ... i understand you have to let people know before you make changes but it still doesnt make sense , not to me anyway
upvoted 2 times
...
marcperrero
1 year, 1 month ago
Selected Answer: B
: While documenting changes and submitting them through change management is good practice for tracking modifications, it does not directly prevent the issue of servers becoming unreachable. It's more about procedural control than technical prevention.
upvoted 2 times
...
Dapsie
1 year, 1 month ago
Selected Answer: B
To prevent this issue, the best thing to do is to test the policy in a non-PROD environment. Even if you submit a change request(The first step in the process), it still makes sense to test before deployment. A change approval won't prevent this issue.
upvoted 1 times
...
Gigi42
1 year, 2 months ago
I have to look over my notes from A+. I believe that before anyone can make changes within the network, a request needs to be implemented. You can't can't go about making changing. Look what he did?
upvoted 2 times
...
Marleigh
1 year, 2 months ago
Selected Answer: B
Despite what everyone is saying, I still think it is B. I don't see why it isn't possible to test policies in a segmented/isolated/whatever network away from prod. Like what was the point about learning of VLANs if we are just going to pretend they dont exist for these questions? Maybe this is showing my lack of IRL network experience. But, I also already have my net+, and I dont see this as unrealistic or impractical. So I will stick to my gut and say B.
upvoted 1 times
...
Mehe323
1 year, 3 months ago
Selected Answer: B
I think is should be B, don't you need to present something to management and state the reason why this is the best solution? So, you do B before doing A?
upvoted 1 times
...
scoobysnack209
1 year, 3 months ago
In Palo Alto Firewall you can test the policy before you commit. The answer is B
upvoted 2 times
Mehe323
1 year, 3 months ago
Agreed. Also A doesn't do anything directly to address the issue. I think B is the step before A.
upvoted 2 times
...
...
spearous
1 year, 3 months ago
Selected Answer: A
A should be correct. yes, like other said, B is too general, and for network, you can't really test firewall in a test env. the network/number of servers/server IPs are entirely different between prod and test.
upvoted 1 times
...
AbdullahMohammad251
1 year, 3 months ago
I would go with B Applying the "deny any" policy in a real environment would still make the servers unreachable even after getting approval from the change management team. We must use sandboxing to test the policy in a non-productive environment before applying it to our systems.
upvoted 2 times
...
russian
1 year, 3 months ago
Selected Answer: B
Chat GPT: "B. Testing the policy in a non-production environment before enabling the policy in the production network. Explanation: Testing the policy in a non-production environment allows the technician to assess its impact and ensure that it does not cause unintended consequences, such as making company servers unreachable. By testing in a controlled environment first, any issues or conflicts can be identified and addressed before implementing the policy in the production network. Documenting the new policy in a change request and submitting it to change management (Option A) is a good practice for tracking changes but may not necessarily prevent the issue from occurring. Disabling intrusion prevention signatures on the "deny any" policy (Option C) is unrelated to ensuring that the policy does not affect server accessibility. Including an "allow any" policy above the "deny any" policy (Option D) would negate the purpose of the "deny any" policy and could potentially introduce security risks."
upvoted 2 times
...
MF757
1 year, 5 months ago
Selected Answer: B
Testing the policy in a non-production environment before deploying it in the production network would help identify any potential issues or unintended consequences, such as causing several company servers to become unreachable.
upvoted 1 times
...
shaneo007
1 year, 6 months ago
Answer B I think it would be best to test the new policy first for any issue. Then . Documenting the new policy in a change request and submitting the request to change management.
upvoted 1 times
...
Yomzie
1 year, 6 months ago
The correct answer is option A. Before any drastic change is implemented in a PROD environment, a Change Management Request is first raised. The process of approval would factor in what the overall business impact would be, and that helps to determine when the change should be carried out, and what the Rollback Plan would be if need be.
upvoted 2 times
...
Titanbug
1 year, 6 months ago
Selected Answer: B
In order to avoid problems such as rendering company servers inaccessible, it is essential to thoroughly test any modifications, particularly a "deny any" policy, in a non-production or test environment prior to implementing it on the production network. This enables the technician to discover and address any unintended repercussions or problems before they affect active systems.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...