While troubleshooting a firewall configuration, a technician determines that a “deny any” policy should be added to the bottom of the ACL. The technician updates the policy, but the new policy causes several company servers to become unreachable. Which of the following actions would prevent this issue?
Choose an answer
Tap an option to check your answer.
Correct answer: Testing the policy in a non-production environment before enabling the policy in the production network.
Why this is the answer
Testing the policy in a non-production environment is crucial because it allows the technician to observe the policy's effects without impacting live services. This "test before deploy" methodology is a best practice in network security and change management, preventing unintended outages like the one described. Documenting the policy in a change request is important for record-keeping and approval but doesn't prevent the technical issue itself. Disabling IPS signatures is irrelevant to a "deny any" firewall policy's impact on server reachability. Including an "allow any" policy above "deny any" would negate the security purpose of "deny any" by permitting all traffic, which is not a solution to the problem of servers becoming unreachable due to an overly restrictive deny rule.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed